Please wait
Version: 19 August 2026
This Privacy and Data Protection Policy explains how MEDNEURO SRL collects, uses, stores, transfers and protects the personal data of patients and users of the ALFMED Virtual Clinic platform, available at https://clinicavirtuala.alfmed.ro.
This Policy has been prepared in accordance with Regulation (EU) 2016/679 on the protection of personal data (“GDPR”), Law no. 190/2018, applicable Romanian healthcare legislation and other relevant legal provisions.
The controller of personal data is:
MEDNEURO SRL
Registered office: Bld. Dacia no. 137, building 17, entrance 1, apartment 3, Craiova, Dolj County, postal code 200048, Romania
Tax Identification Number: 34565441
Trade Registry no.: J16/823/2015
E-mail: contact@alfmed.ro
Telephone: 0351 429 158
MEDNEURO SRL determines the essential purposes and means of processing personal data in connection with the provision of medical services through ALFMED Virtual Clinic and acts as the data controller within the meaning of the GDPR.
This Policy applies to processing activities carried out in connection with:
MEDNEURO SRL has appointed a Data Protection Officer (“DPO”).
For any questions regarding the processing of personal data or for exercising rights under the GDPR, the Data Protection Officer may be contacted at:
contact@alfmed.ro
Data subjects may contact the DPO directly regarding any matter concerning the processing of their personal data and the exercise of their rights under applicable data protection legislation.
For the operation of the Platform and provision of services, MEDNEURO SRL may disclose or allow access to certain personal data only to the extent necessary for the relevant purpose and subject to applicable confidentiality and security obligations.
EVOTECH-IT SRL provides the Telemedica software solution and the technical services required for the configuration, maintenance, support and hosting of the Platform. The application is hosted on server infrastructure provided by EVOTECH-IT SRL and is accessed through MEDNEURO SRL’s internet domain.
As part of the technical services provided, EVOTECH-IT SRL may perform operations necessary for the administration and maintenance of the database, including, where applicable, database reindexing, data replication and the creation of backup copies.
To the extent that it processes personal data on behalf of MEDNEURO SRL, EVOTECH-IT SRL acts as a data processor in accordance with Article 28 GDPR and the data processing agreement concluded between the parties.
EVOTECH-IT SRL processes personal data only for the purpose of providing the contracted services and in accordance with MEDNEURO SRL’s instructions, within the limits established by the contract and applicable law.
EVOTECH-IT SRL may engage sub-processors in accordance with the applicable contractual and legal requirements and is required to inform MEDNEURO SRL of the appointment or replacement of such sub-processors and to impose on them data protection obligations at least equivalent to those applicable to EVOTECH-IT SRL.
Medical data are accessible to doctors providing services through MEDNEURO SRL only to the extent necessary for the provision of medical care.
Doctors are required to comply with professional secrecy, confidentiality of medical information and all applicable legal and professional obligations concerning the protection of patient data.
MEDNEURO SRL uses Google Workspace for e-mail services associated with the alfmed.ro domain.
Accordingly, data contained in messages sent to or from contact@alfmed.ro, including any documents attached by the patient, may be processed through the Google Workspace infrastructure for the purpose of providing electronic communication services.
Patients are encouraged not to send by e-mail more medical information than is necessary for the relevant request.
The Platform uses Google reCAPTCHA to protect forms and Platform functionalities against automated access, spam, fraud and other forms of abuse.
When reCAPTCHA is used, technical data may be processed, including IP address, information about the browser and device, data relating to interaction with the Platform and technical identifiers or cookies.
Further information is available in the Cookie Policy.
Online payments are processed through NETOPIA Payments, provided by NETOPIA FINANCIAL SERVICES S.A.
For payment processing activities for which it determines its own purposes and means of processing, NETOPIA acts as an independent data controller in accordance with its own privacy information.
MEDNEURO SRL does not receive or store the full payment card number, card expiry date or CVV code.
MEDNEURO SRL may transmit to NETOPIA the information strictly necessary to initiate and identify the transaction, such as name, contact details, transaction amount, order identifier or other information required for payment processing.
Personal data may be disclosed to public authorities, courts, medical professional bodies, tax authorities or other entities where disclosure is required by law, necessary for compliance with a legal obligation or required for the establishment, exercise or defence of legal claims.
MEDNEURO SRL does not disclose patient data to third parties for marketing or advertising purposes.
The categories of data actually processed depend on the service used and the information required in the particular circumstances.
We may process:
The CNP is used for the unambiguous identification of the patient and for the appropriate organisation of medical and administrative records.
Depending on the medical service, we may process:
Health data are special categories of personal data and benefit from the additional protection provided by Article 9 GDPR and legislation governing medical confidentiality and professional secrecy.
We may process:
Authentication credentials are protected through appropriate technical and cryptographic mechanisms and are not used by MEDNEURO SRL for unrelated purposes.
We may process:
Full payment card details are processed through NETOPIA infrastructure and are not stored by MEDNEURO SRL.
When the patient contacts MEDNEURO SRL, we may process:
MEDNEURO SRL does not make audio or video recordings of consultations provided through ALFMED Virtual Clinic.
Personal data are obtained primarily:
MEDNEURO SRL does not collect medical information about patients from public sources for profiling or marketing purposes.
Personal data are processed for creating the account, selecting the service and doctor, managing the booking and entering into the contract for medical services.
Legal basis: Article 6(1)(b) GDPR – performance of a contract or taking steps at the request of the data subject prior to entering into a contract.
Identification data and health data are processed for assessing the patient, providing the telemedicine consultation, establishing or guiding a diagnosis, recommending investigations or treatment and documenting the medical act.
Legal basis: Article 6(1)(b) and/or Article 6(1)(c) GDPR, as applicable, together with Article 9(2)(h) GDPR – processing necessary for the provision of healthcare and the management of health services.
Processing is carried out subject to professional secrecy and the legislation applicable to the medical profession.
The CNP is processed for the unambiguous identification of the patient and for correctly linking medical services and documents to the person concerned.
The processing of CNP and other national identifiers is carried out in accordance with the GDPR and Law no. 190/2018.
Contact details are used for booking confirmations, information required for the consultation, transmission of documents relating to the service, administrative notifications and responses to patient requests.
Legal basis: Article 6(1)(b) GDPR and, where applicable, Article 6(1)(c) GDPR.
MEDNEURO SRL does not use data provided through ALFMED Virtual Clinic for newsletters, advertisements or other marketing communications.
Personal data are processed for issuing tax documents, recording transactions and complying with fiscal and accounting obligations.
Legal basis: Article 6(1)(c) GDPR – compliance with a legal obligation.
Technical data such as IP addresses, logs, session identifiers and data processed through reCAPTCHA may be used to protect accounts and the Platform, detect security incidents, prevent automated or fraudulent access and investigate incidents.
Legal basis: Article 6(1)(f) GDPR – MEDNEURO SRL’s legitimate interest in ensuring the security of its services and data.
Personal data may be processed for handling complaints, managing disputes and establishing, exercising or defending legal claims.
Legal basis: Article 6(1)(c) and/or Article 6(1)(f) GDPR and, in relation to health data, Article 9(2)(f) GDPR, where applicable.
The patient’s express consent to the provision of a service by telemedicine constitutes consent to the particular method through which the medical act is provided.
It must not be confused with consent under the GDPR as a legal basis for certain data processing activities.
The processing of data necessary for the provision of healthcare is not generally based on the patient’s GDPR consent but on the legal bases described in Article 6 above.
Where a specific processing activity is based on GDPR consent, such consent shall be requested separately for a specific purpose and may be withdrawn in accordance with applicable law.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal and does not require deletion of data that must be retained pursuant to a legal obligation.
Certain personal data are mandatory for account creation, patient identification and the safe provision of medical services.
These include the identification and contact data requested by the Platform, including the CNP, together with any medical information the doctor considers necessary for assessing the case.
MEDNEURO SRL applies the principle of data minimisation and requests only the information necessary for the relevant purposes.
Failure to provide mandatory information may make it impossible to create an account, correctly identify the patient, make a booking or provide the medical service.
The patient is not required to provide medical information that is not relevant to the requested service.
User Accounts may only be created by persons who are at least 18 years old.
For a minor patient, the account and booking are managed by the parent or legal representative.
The minor’s personal data are processed only to the extent necessary for the provision of the medical service and compliance with the applicable legal and professional obligations.
Consent to the medical act and to its provision by telemedicine is obtained in accordance with the specific legal rules applicable to minors and their legal representatives.
MEDNEURO SRL does not assume that all processing operations performed through its technical providers take place exclusively in Romania or within the European Economic Area.
With regard to the Platform’s technical provider, the agreement concluded between MEDNEURO SRL and EVOTECH-IT SRL contains specific obligations concerning the protection of personal data transfers and prohibits EVOTECH-IT SRL from disclosing or transferring personal data to third parties located in countries outside the European Union or the European Economic Area that do not provide an adequate level of protection, subject to the contractual terms and applicable data protection legislation.
Certain providers used for the operation of the Platform and communication services, particularly global providers such as Google, may process certain personal data through infrastructure located outside the European Economic Area.
Where processing involves a transfer of personal data to a country outside the European Economic Area, such transfer shall take place only in accordance with Chapter V GDPR and, where applicable, on the basis of:
The data subject may request further information regarding safeguards applicable to a particular transfer by contacting contact@alfmed.ro.
MEDNEURO SRL does not retain personal data indefinitely.
Retention periods are determined according to the nature of the data, the purpose of processing, applicable legal obligations, the need to ensure continuity of medical care and the periods during which legal claims may be brought or defended.
Data and documents forming part of the patient’s medical record are retained for the periods required by healthcare legislation, professional rules and archiving requirements applicable to the relevant category of medical document.
Not all medical documents are subject to a single uniform statutory retention period.
Where legislation provides a specific retention period, MEDNEURO SRL complies with that period.
Where no specific statutory period applies, medical data are retained for as long as necessary to ensure continuity of care, document the medical act, comply with professional obligations and protect legitimate legal interests, with periodic review of the need for continued retention.
Deletion of the User Account does not result in deletion of medical records which must be retained pursuant to law or professional obligations.
Mandatory accounting records and supporting documents underlying accounting entries are retained, under the accounting legislation currently in force, for 5 years, calculated from 1 July of the year following the end of the financial year in which they were prepared, unless a specific legal provision requires another period.
Information required to evidence the contractual relationship, bookings, cancellations, refunds and complaints may generally be retained for 3 years after completion of the relevant relationship, corresponding to the general limitation period, or for longer where a dispute, investigation or legal obligation justifies continued retention.
Data required solely for account administration are retained for as long as the account remains active.
Following account closure, data which do not need to be retained for medical, legal, fiscal or legal-claims purposes shall be deleted or anonymised within a reasonable period.
Technical logs and security information are retained for the period necessary to prevent, identify and investigate security incidents, depending on the nature of the event and the technical configuration of the Platform.
Where a log is relevant to the investigation of an incident, fraud, complaint or dispute, it may be retained until that matter has been finally resolved.
Messages are retained for as long as necessary to handle the relevant request and, where they have medical, contractual, fiscal or legal relevance, for the retention period applicable to the relevant category of information.
Upon expiry of the applicable period, personal data are deleted, anonymised or archived as required by law.
Backups may temporarily contain data deleted from active systems until such data are overwritten in accordance with the applicable technical backup cycle and shall not be reused for unrelated purposes.
Given the sensitive nature of health data, MEDNEURO SRL adopts, and requires its processors to adopt, technical and organisational measures appropriate to the level of risk.
The contractual arrangements with the Platform’s technical provider include obligations to implement and maintain technical and organisational measures appropriate to the risks associated with the processing, to protect the integrity and security of the database, to support service continuity, to manage personal data security incidents and to cooperate with MEDNEURO SRL in relation to data protection requests and incidents.
Such measures may include, where appropriate:
Access to medical information is limited to persons who require such information to perform their professional or legal duties.
No information system can guarantee the complete elimination of all security risks; however, security measures are assessed and adjusted in light of the identified risks.
Subject to the conditions and limitations set out in the GDPR, the data subject may have:
The right to erasure is not absolute. MEDNEURO SRL may refuse deletion where continued retention is necessary for compliance with a legal obligation, the provision and documentation of healthcare, mandatory archiving or the establishment, exercise or defence of legal claims.
Requests may be submitted to the DPO at:
contact@alfmed.ro
MEDNEURO SRL may request additional information where necessary to verify the identity of the person making the request.
We shall respond without undue delay and in any event within one month of receipt of the request.
Where justified by the complexity or number of requests, this period may be extended by up to two additional months, and the data subject shall be informed of the extension and the reasons for it within the initial one-month period.
The Platform uses cookies and similar technologies necessary for the operation, authentication and security of the service.
The Platform also uses Google reCAPTCHA to protect against spam and automated access. In connection with this integration, Google may use its own identifiers and cookies and may process technical information concerning the User and their device.
As of the date of this version, MEDNEURO SRL does not use ALFMED Virtual Clinic for behavioural advertising, remarketing or cookie-based marketing campaigns.
The types of cookies used, their provider, purpose, duration and available management options are described separately in the Cookie Policy.
In the event of a personal data breach, MEDNEURO SRL shall promptly assess the nature of the incident and the risk to the rights and freedoms of the affected individuals.
Where the conditions laid down by the GDPR are met, MEDNEURO SRL shall notify the Romanian National Supervisory Authority for Personal Data Processing without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach.
Where the breach is likely to result in a high risk to the rights and freedoms of the data subject, MEDNEURO SRL shall also inform the affected individual without undue delay, in accordance with the GDPR.
MEDNEURO SRL may update this Policy to reflect:
The version currently in force shall remain permanently available through the Platform.
In the event of significant changes, Users may be informed through the Platform, by e-mail or by other appropriate means.
For questions regarding this Policy, for exercising rights under the GDPR or for contacting the Data Protection Officer:
MEDNEURO SRL – ALFMED Virtual Clinic
E-mail: contact@alfmed.ro
Telephone: 0351 429 158
Last updated: 19 August 2026
Please wait