Please wait

 

Privacy and Data Protection Policy – ALFMED Virtual Clinic

Version: 19 August 2026

This Privacy and Data Protection Policy explains how MEDNEURO SRL collects, uses, stores, transfers and protects the personal data of patients and users of the ALFMED Virtual Clinic platform, available at https://clinicavirtuala.alfmed.ro.

This Policy has been prepared in accordance with Regulation (EU) 2016/679 on the protection of personal data (“GDPR”), Law no. 190/2018, applicable Romanian healthcare legislation and other relevant legal provisions.

1. Who is the Data Controller

The controller of personal data is:

MEDNEURO SRL
Registered office: Bld. Dacia no. 137, building 17, entrance 1, apartment 3, Craiova, Dolj County, postal code 200048, Romania
Tax Identification Number: 34565441
Trade Registry no.: J16/823/2015
E-mail: contact@alfmed.ro
Telephone: 0351 429 158

MEDNEURO SRL determines the essential purposes and means of processing personal data in connection with the provision of medical services through ALFMED Virtual Clinic and acts as the data controller within the meaning of the GDPR.

This Policy applies to processing activities carried out in connection with:

  • creation and management of the User Account;
  • patient identification;
  • booking of medical services;
  • provision of consultations and other telemedicine services;
  • uploading and management of medical documents;
  • communication between the patient and MEDNEURO SRL;
  • payment and invoicing;
  • handling of requests, complaints, cancellations and refunds;
  • security and operation of the Platform.

2. Data Protection Officer

MEDNEURO SRL has appointed a Data Protection Officer (“DPO”).

For any questions regarding the processing of personal data or for exercising rights under the GDPR, the Data Protection Officer may be contacted at:

contact@alfmed.ro

Data subjects may contact the DPO directly regarding any matter concerning the processing of their personal data and the exercise of their rights under applicable data protection legislation.

3. Processors, Service Providers and Other Data Recipients

For the operation of the Platform and provision of services, MEDNEURO SRL may disclose or allow access to certain personal data only to the extent necessary for the relevant purpose and subject to applicable confidentiality and security obligations.

3.1. EVOTECH-IT SRL

EVOTECH-IT SRL provides the Telemedica software solution and the technical services required for the configuration, maintenance, support and hosting of the Platform. The application is hosted on server infrastructure provided by EVOTECH-IT SRL and is accessed through MEDNEURO SRL’s internet domain.

As part of the technical services provided, EVOTECH-IT SRL may perform operations necessary for the administration and maintenance of the database, including, where applicable, database reindexing, data replication and the creation of backup copies.

To the extent that it processes personal data on behalf of MEDNEURO SRL, EVOTECH-IT SRL acts as a data processor in accordance with Article 28 GDPR and the data processing agreement concluded between the parties.

EVOTECH-IT SRL processes personal data only for the purpose of providing the contracted services and in accordance with MEDNEURO SRL’s instructions, within the limits established by the contract and applicable law.

EVOTECH-IT SRL may engage sub-processors in accordance with the applicable contractual and legal requirements and is required to inform MEDNEURO SRL of the appointment or replacement of such sub-processors and to impose on them data protection obligations at least equivalent to those applicable to EVOTECH-IT SRL.

3.2. Doctors

Medical data are accessible to doctors providing services through MEDNEURO SRL only to the extent necessary for the provision of medical care.

Doctors are required to comply with professional secrecy, confidentiality of medical information and all applicable legal and professional obligations concerning the protection of patient data.

3.3. Google Workspace

MEDNEURO SRL uses Google Workspace for e-mail services associated with the alfmed.ro domain.

Accordingly, data contained in messages sent to or from contact@alfmed.ro, including any documents attached by the patient, may be processed through the Google Workspace infrastructure for the purpose of providing electronic communication services.

Patients are encouraged not to send by e-mail more medical information than is necessary for the relevant request.

3.4. Google reCAPTCHA

The Platform uses Google reCAPTCHA to protect forms and Platform functionalities against automated access, spam, fraud and other forms of abuse.

When reCAPTCHA is used, technical data may be processed, including IP address, information about the browser and device, data relating to interaction with the Platform and technical identifiers or cookies.

Further information is available in the Cookie Policy.

3.5. NETOPIA Payments

Online payments are processed through NETOPIA Payments, provided by NETOPIA FINANCIAL SERVICES S.A.

For payment processing activities for which it determines its own purposes and means of processing, NETOPIA acts as an independent data controller in accordance with its own privacy information.

MEDNEURO SRL does not receive or store the full payment card number, card expiry date or CVV code.

MEDNEURO SRL may transmit to NETOPIA the information strictly necessary to initiate and identify the transaction, such as name, contact details, transaction amount, order identifier or other information required for payment processing.

3.6. Public Authorities and Other Entities

Personal data may be disclosed to public authorities, courts, medical professional bodies, tax authorities or other entities where disclosure is required by law, necessary for compliance with a legal obligation or required for the establishment, exercise or defence of legal claims.

MEDNEURO SRL does not disclose patient data to third parties for marketing or advertising purposes.

4. Categories of Personal Data We Process

The categories of data actually processed depend on the service used and the information required in the particular circumstances.

4.1. Identification and Contact Data

We may process:

  • first name and surname;
  • Romanian Personal Identification Number (CNP);
  • date of birth;
  • sex;
  • address;
  • identity document series and number, where verification is necessary;
  • telephone number;
  • e-mail address;
  • information relating to the legal representative, where services are provided to a minor or legally represented person.

The CNP is used for the unambiguous identification of the patient and for the appropriate organisation of medical and administrative records.

4.2. Health Data

Depending on the medical service, we may process:

  • symptoms and reason for consultation;
  • personal and family medical history;
  • diagnoses;
  • allergies;
  • current or previous treatments;
  • laboratory test results;
  • electrocardiograms and other investigations;
  • medical images;
  • medical letters;
  • hospital discharge documents;
  • prescriptions and recommendations;
  • other medical documents uploaded by the patient;
  • answers and information provided through medical questionnaires available on the Platform;
  • messages sent through the internal messaging system or webchat where their content is relevant to medical assessment or care;
  • medical notes entered by the doctor in relation to the patient;
  • online consultation reports;
  • referrals, prescriptions, medical letters, recommendations and other medical documents generated through the Platform;
  • information relating to the history of consultations and medical services provided through the Platform
  • information and conclusions resulting from the consultation;
  • diagnoses, recommendations and other documents prepared by the doctor.

Health data are special categories of personal data and benefit from the additional protection provided by Article 9 GDPR and legislation governing medical confidentiality and professional secrecy.

4.3. Account and Platform Usage Data

We may process:

  • account identifier;
  • authentication information;
  • booking history;
  • date and time of access;
  • IP address;
  • device, operating system and browser information;
  • technical logs and events;
  • session tokens and identifiers;
  • information required for account security.
  • booking and cancellation history;
  • history of access to consultations;
  • use of internal messaging and webchat functions;
  • transmission, receipt and downloading of documents through the Platform;
  • completion of questionnaires available on the Platform;
  • notifications and alerts generated by the Platform;
  • technical events associated with the use of Platform functionalities.

Authentication credentials are protected through appropriate technical and cryptographic mechanisms and are not used by MEDNEURO SRL for unrelated purposes.

4.4. Payment and Invoicing Data

We may process:

  • the service purchased;
  • amount and currency;
  • transaction date and time;
  • transaction identifier;
  • payment status;
  • data required for issuing tax documents.

Full payment card details are processed through NETOPIA infrastructure and are not stored by MEDNEURO SRL.

4.5. Communications and Requests

When the patient contacts MEDNEURO SRL, we may process:

  • the content of the message;
  • contact information;
  • booking information;
  • medical documents or information voluntarily submitted;
  • information required to handle complaints, cancellations or refunds.

4.6. Audio and Video Recordings

MEDNEURO SRL does not make audio or video recordings of consultations provided through ALFMED Virtual Clinic.

5. Sources of Personal Data

Personal data are obtained primarily:

  • directly from the patient;
  • from the patient’s parent or legal representative;
  • from the doctor as a result of the medical act;
  • automatically through use of the Platform, in the case of technical data;
  • from the payment processor in relation to payment confirmation and transaction status;
  • from authorities or other sources where permitted or required by law.

MEDNEURO SRL does not collect medical information about patients from public sources for profiling or marketing purposes.

6. Purposes and Legal Bases of Processing

6.1. Account Creation and Booking Management

Personal data are processed for creating the account, selecting the service and doctor, managing the booking and entering into the contract for medical services.

Legal basis: Article 6(1)(b) GDPR – performance of a contract or taking steps at the request of the data subject prior to entering into a contract.

6.2. Provision of Medical Services

Identification data and health data are processed for assessing the patient, providing the telemedicine consultation, establishing or guiding a diagnosis, recommending investigations or treatment and documenting the medical act.

Legal basis: Article 6(1)(b) and/or Article 6(1)(c) GDPR, as applicable, together with Article 9(2)(h) GDPR – processing necessary for the provision of healthcare and the management of health services.

Processing is carried out subject to professional secrecy and the legislation applicable to the medical profession.

6.3. Patient Identification and Processing of CNP

The CNP is processed for the unambiguous identification of the patient and for correctly linking medical services and documents to the person concerned.

The processing of CNP and other national identifiers is carried out in accordance with the GDPR and Law no. 190/2018.

6.4. Communication with the Patient

Contact details are used for booking confirmations, information required for the consultation, transmission of documents relating to the service, administrative notifications and responses to patient requests.

Legal basis: Article 6(1)(b) GDPR and, where applicable, Article 6(1)(c) GDPR.

MEDNEURO SRL does not use data provided through ALFMED Virtual Clinic for newsletters, advertisements or other marketing communications.

6.5. Invoicing and Financial Records

Personal data are processed for issuing tax documents, recording transactions and complying with fiscal and accounting obligations.

Legal basis: Article 6(1)(c) GDPR – compliance with a legal obligation.

6.6. Platform Security and Prevention of Abuse

Technical data such as IP addresses, logs, session identifiers and data processed through reCAPTCHA may be used to protect accounts and the Platform, detect security incidents, prevent automated or fraudulent access and investigate incidents.

Legal basis: Article 6(1)(f) GDPR – MEDNEURO SRL’s legitimate interest in ensuring the security of its services and data.

6.7. Complaints and Defence of Legal Rights

Personal data may be processed for handling complaints, managing disputes and establishing, exercising or defending legal claims.

Legal basis: Article 6(1)(c) and/or Article 6(1)(f) GDPR and, in relation to health data, Article 9(2)(f) GDPR, where applicable.

7. Consent to Telemedicine and Consent under the GDPR

The patient’s express consent to the provision of a service by telemedicine constitutes consent to the particular method through which the medical act is provided.

It must not be confused with consent under the GDPR as a legal basis for certain data processing activities.

The processing of data necessary for the provision of healthcare is not generally based on the patient’s GDPR consent but on the legal bases described in Article 6 above.

Where a specific processing activity is based on GDPR consent, such consent shall be requested separately for a specific purpose and may be withdrawn in accordance with applicable law.

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal and does not require deletion of data that must be retained pursuant to a legal obligation.

8. Mandatory Data and Consequences of Failure to Provide Them

Certain personal data are mandatory for account creation, patient identification and the safe provision of medical services.

These include the identification and contact data requested by the Platform, including the CNP, together with any medical information the doctor considers necessary for assessing the case.

MEDNEURO SRL applies the principle of data minimisation and requests only the information necessary for the relevant purposes.

Failure to provide mandatory information may make it impossible to create an account, correctly identify the patient, make a booking or provide the medical service.

The patient is not required to provide medical information that is not relevant to the requested service.

9. Personal Data of Minors

User Accounts may only be created by persons who are at least 18 years old.

For a minor patient, the account and booking are managed by the parent or legal representative.

The minor’s personal data are processed only to the extent necessary for the provision of the medical service and compliance with the applicable legal and professional obligations.

Consent to the medical act and to its provision by telemedicine is obtained in accordance with the specific legal rules applicable to minors and their legal representatives.

10. International Transfers of Personal Data

MEDNEURO SRL does not assume that all processing operations performed through its technical providers take place exclusively in Romania or within the European Economic Area.

With regard to the Platform’s technical provider, the agreement concluded between MEDNEURO SRL and EVOTECH-IT SRL contains specific obligations concerning the protection of personal data transfers and prohibits EVOTECH-IT SRL from disclosing or transferring personal data to third parties located in countries outside the European Union or the European Economic Area that do not provide an adequate level of protection, subject to the contractual terms and applicable data protection legislation.

Certain providers used for the operation of the Platform and communication services, particularly global providers such as Google, may process certain personal data through infrastructure located outside the European Economic Area.

Where processing involves a transfer of personal data to a country outside the European Economic Area, such transfer shall take place only in accordance with Chapter V GDPR and, where applicable, on the basis of:

  • an adequacy decision adopted by the European Commission;
  • the EU-U.S. Data Privacy Framework, for eligible recipients and transfers;
  • Standard Contractual Clauses approved by the European Commission;
  • another lawful transfer mechanism provided by the GDPR;
  • supplementary safeguards, where required.

The data subject may request further information regarding safeguards applicable to a particular transfer by contacting contact@alfmed.ro.

11. Retention Periods

MEDNEURO SRL does not retain personal data indefinitely.

Retention periods are determined according to the nature of the data, the purpose of processing, applicable legal obligations, the need to ensure continuity of medical care and the periods during which legal claims may be brought or defended.

11.1. Medical Data and Medical Records

Data and documents forming part of the patient’s medical record are retained for the periods required by healthcare legislation, professional rules and archiving requirements applicable to the relevant category of medical document.

Not all medical documents are subject to a single uniform statutory retention period.

Where legislation provides a specific retention period, MEDNEURO SRL complies with that period.

Where no specific statutory period applies, medical data are retained for as long as necessary to ensure continuity of care, document the medical act, comply with professional obligations and protect legitimate legal interests, with periodic review of the need for continued retention.

Deletion of the User Account does not result in deletion of medical records which must be retained pursuant to law or professional obligations.

11.2. Accounting and Financial Documents

Mandatory accounting records and supporting documents underlying accounting entries are retained, under the accounting legislation currently in force, for 5 years, calculated from 1 July of the year following the end of the financial year in which they were prepared, unless a specific legal provision requires another period.

11.3. Booking, Contract, Cancellation and Complaint Data

Information required to evidence the contractual relationship, bookings, cancellations, refunds and complaints may generally be retained for 3 years after completion of the relevant relationship, corresponding to the general limitation period, or for longer where a dispute, investigation or legal obligation justifies continued retention.

11.4. User Account Data

Data required solely for account administration are retained for as long as the account remains active.

Following account closure, data which do not need to be retained for medical, legal, fiscal or legal-claims purposes shall be deleted or anonymised within a reasonable period.

11.5. Logs and Security Data

Technical logs and security information are retained for the period necessary to prevent, identify and investigate security incidents, depending on the nature of the event and the technical configuration of the Platform.

Where a log is relevant to the investigation of an incident, fraud, complaint or dispute, it may be retained until that matter has been finally resolved.

11.6. E-mail and Correspondence

Messages are retained for as long as necessary to handle the relevant request and, where they have medical, contractual, fiscal or legal relevance, for the retention period applicable to the relevant category of information.

Upon expiry of the applicable period, personal data are deleted, anonymised or archived as required by law.

Backups may temporarily contain data deleted from active systems until such data are overwritten in accordance with the applicable technical backup cycle and shall not be reused for unrelated purposes.

12. Data Security

Given the sensitive nature of health data, MEDNEURO SRL adopts, and requires its processors to adopt, technical and organisational measures appropriate to the level of risk.

The contractual arrangements with the Platform’s technical provider include obligations to implement and maintain technical and organisational measures appropriate to the risks associated with the processing, to protect the integrity and security of the database, to support service continuity, to manage personal data security incidents and to cooperate with MEDNEURO SRL in relation to data protection requests and incidents.

Such measures may include, where appropriate:

  • use of encrypted connections;
  • role-based and need-to-know access controls;
  • User authentication;
  • protection of credentials through cryptographic mechanisms;
  • logging of access and relevant events;
  • backups;
  • measures against unauthorised access;
  • measures against loss, alteration or unauthorised disclosure;
  • training of persons who have access to personal data;
  • contractual confidentiality and data protection obligations.

Access to medical information is limited to persons who require such information to perform their professional or legal duties.

No information system can guarantee the complete elimination of all security risks; however, security measures are assessed and adjusted in light of the identified risks.

13. Rights of Data Subjects

Subject to the conditions and limitations set out in the GDPR, the data subject may have:

  • the right of access to personal data and information regarding their processing;
  • the right to rectification of inaccurate or incomplete data;
  • the right to erasure, where the applicable legal conditions are met;
  • the right to restriction of processing;
  • the right to data portability, where applicable;
  • the right to object, particularly to processing based on legitimate interests;
  • the right to withdraw consent, where the relevant processing is based on consent;
  • the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing;
  • the right to seek judicial remedies before the competent courts.

The right to erasure is not absolute. MEDNEURO SRL may refuse deletion where continued retention is necessary for compliance with a legal obligation, the provision and documentation of healthcare, mandatory archiving or the establishment, exercise or defence of legal claims.

Requests may be submitted to the DPO at:

contact@alfmed.ro

MEDNEURO SRL may request additional information where necessary to verify the identity of the person making the request.

We shall respond without undue delay and in any event within one month of receipt of the request.

Where justified by the complexity or number of requests, this period may be extended by up to two additional months, and the data subject shall be informed of the extension and the reasons for it within the initial one-month period.

14. Cookies and Similar Technologies

The Platform uses cookies and similar technologies necessary for the operation, authentication and security of the service.

The Platform also uses Google reCAPTCHA to protect against spam and automated access. In connection with this integration, Google may use its own identifiers and cookies and may process technical information concerning the User and their device.

As of the date of this version, MEDNEURO SRL does not use ALFMED Virtual Clinic for behavioural advertising, remarketing or cookie-based marketing campaigns.

The types of cookies used, their provider, purpose, duration and available management options are described separately in the Cookie Policy.

15. Personal Data Breaches

In the event of a personal data breach, MEDNEURO SRL shall promptly assess the nature of the incident and the risk to the rights and freedoms of the affected individuals.

Where the conditions laid down by the GDPR are met, MEDNEURO SRL shall notify the Romanian National Supervisory Authority for Personal Data Processing without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach.

Where the breach is likely to result in a high risk to the rights and freedoms of the data subject, MEDNEURO SRL shall also inform the affected individual without undue delay, in accordance with the GDPR.

16. Amendments to this Policy

MEDNEURO SRL may update this Policy to reflect:

  • legislative changes;
  • changes to the services provided;
  • changes to technical service providers;
  • changes to the categories of personal data or purposes of processing;
  • changes to the Platform infrastructure;
  • recommendations or decisions issued by competent authorities.

The version currently in force shall remain permanently available through the Platform.

In the event of significant changes, Users may be informed through the Platform, by e-mail or by other appropriate means.

17. Contact

For questions regarding this Policy, for exercising rights under the GDPR or for contacting the Data Protection Officer:

MEDNEURO SRL – ALFMED Virtual Clinic
E-mail: contact@alfmed.ro
Telephone: 0351 429 158

Last updated: 19 August 2026

Please wait