Legal

Terms, Privacy Policy & Cookies

The four documents that govern the use of this service: what we promise, what we do with the data, which cookies we set, and what happens to a clinic's patient data. Written to be read, not skimmed.

Version 2026-10-09 In force since 9 October 2026

1. Terms of Service

What the service is, what you may do with it, what it costs, and who is responsible for what.

1.1 The service

A web application for running a clinic: patient records, appointments, visits, laboratory results, documents, consents, billing, and an AI assistant that drafts entries into those records.

It is record-keeping software. It is not a medical device, it does not diagnose, and it is not a way of reaching anyone in an emergency.

1.2 Your account

You may register a clinic if you are authorised to act for it. You give accurate details, you keep the sign-in details to yourself, and you are responsible for what the users you create do inside the account.

One account belongs to one clinic. No clinic can see another clinic's data.

1.3 What you may not do

The service may not be used to:

  • do anything unlawful, or enter data you have no right to hold;
  • reach another clinic's records, or work around the permissions you have been given;
  • upload code intended to damage the service or to copy it;
  • resell or sub-licence the service without a written agreement with us;
  • let the assistant make clinical decisions that no clinician has read and confirmed.

1.4 Clinical responsibility, and the assistant

The assistant proposes; the clinician decides. It reads the record and drafts text, results and appointments, but it can be wrong, and it can miss something a person would notice.

Nothing it produces is saved until a user confirms it, and nobody should confirm anything they have not read. The medical record, and the care of the patient, remain the clinic's responsibility.

1.5 Fees, tax and AI credits

The plan is billed per clinic, per month. Prices are shown without VAT, which is charged as the law requires.

Using the assistant draws on prepaid credits, charged by what each request actually costs. Credits that are not used stay on the account.

If an invoice is not paid we may suspend the account, after telling you. A suspension does not delete data.

1.6 Availability and support

We aim for continuous availability but we do not promise it: the service depends on hosting, networks and third parties. We may interrupt it for maintenance, and we tell you in advance where we can.

Support is by email, and it is answered by people who know the software.

1.7 Your data

The data you enter stays yours, and your patients' rights stay with your patients. We hold the data on your instructions, as your processor.

You can export it at any time while your account is open. The privacy section below says how it is stored, where, and for how long.

1.8 Intellectual property

The software, its interface and its documentation belong to us or to our licensors. Using the service transfers none of it, and the software may not be copied, decompiled or resold.

If you send us an idea, a correction or a suggestion, we may use it without owing you anything for it.

1.9 Our liability

We provide the service with reasonable skill and care. We do not promise it will be free of errors, and we are not responsible for clinical decisions, for data entered incorrectly, or for indirect losses.

Where liability cannot be excluded, ours is limited to the fees paid for the twelve months before the claim. Nothing here limits liability for intent or gross negligence, or anything else that the law does not allow to be limited.

1.10 Suspension, and ending the agreement

You may end the agreement at any time; the account then runs to the end of the month you have paid for.

We may suspend or end it if these terms are broken or an invoice is unpaid, and we tell you why. After the agreement ends, data is kept for as long as the retention schedule allows and then deleted — so export it before you go.

1.11 Changes to these terms

We may change these terms, and we tell you by email or in the application before a change takes effect. The version you accepted is recorded against your account.

Continuing to use the service after a change takes effect means accepting it.

1.12 Which law applies

This agreement is governed by Greek law, and the courts of Athens have jurisdiction. That does not take away any right a consumer has to bring a claim where they live.

2. Privacy Policy

Who is responsible for which data, what is processed and why, where it is kept, how long, and what you can ask for.

2.1 Two roles, and the difference matters

For the patient data inside a clinic's account, the clinic is the controller and we are the processor: we act on the clinic's documented instructions and for no purpose of our own.

For the data of the people who use the service — accounts, billing, support, and visitors to this website — we are the controller. This section covers both.

2.2 What we process as controller, and why

We keep as little as we can, and only for these purposes:

  • account data — name, email address, clinic — to create the account and to run it: the contract;
  • billing data — invoices and payments — to charge for the service and to comply with tax law: the contract, and a legal obligation;
  • technical and usage data — IP address, browser, pages, errors — to keep the service working, to stop abuse and to investigate incidents: our legitimate interest in protecting it;
  • statistics for the public pages — only if you agree to them: your consent;
  • correspondence with us — to answer you: our legitimate interest in supporting the service.

2.3 What we process on a clinic's behalf

The clinic decides what is entered: identity and contact details, the medical record, visits, diagnoses and findings, laboratory results, medication, images and documents, appointments, and the assistant's conversations about a patient.

We use none of it for our own purposes. We do not sell it, we do not share it with advertisers, and we do not train models on it. The clinic answers its patients' requests; we give it the tools to do so — export, correction and anonymisation — and we help when it asks.

2.4 The AI assistant, precisely

Nothing that identifies a patient is sent to a model. A patient is chosen by searching inside the application, and a message that carries an AMKA, a tax number, an identity or passport number, an IBAN, an email address, a phone number, or the name of another patient of the clinic is refused before it leaves: nothing is transmitted, nothing is stored, nothing is charged, and the refusal is written to the audit log.

The name of the patient the conversation is about is replaced with a reference before a request is sent. Inference runs in memory, the provider retains nothing of the request afterwards, and no training is done on the data.

The conversation itself is kept in our own database so that the doctor can read it back, and a scheduled job deletes it after 15 days.

2.5 Where the data is

The application, the database and the encrypted backups run on Hetzner in Germany. Inference runs on Scaleway in Paris. Both are in the European Union, and patient data is not transferred outside it.

Two things do leave the EU, and only these. Card payments are handled by Stripe, whose European entity is in Ireland; the card details never reach us. Statistics for the public pages are collected with Google Analytics, which is loaded only if you accept it, and which may process data in the United States under the EU–US Data Privacy Framework and the standard contractual clauses. Transactional email is sent through ZeptoMail's European endpoint.

Invoices are issued electronically through Elorus, a Greek service, as the tax authority requires.

2.6 How long it is kept

Retention is set deliberately, and it is different for each kind of data:

  • patient files and records — the clinic decides how long it keeps them, may delete any of them at any time, and may set a period after which they are deleted automatically;
  • AI conversations — 15 days, then deleted with their messages;
  • audit log of accesses and changes — kept while the account is open, because accountability has to outlive the data it describes;
  • database backups — 7 days, encrypted with a key separate from the data;
  • invoices — for as long as tax law requires them to be kept;
  • website statistics — for the period configured in our analytics property, and your consent can be withdrawn at any time.

2.7 How it is protected

The measures below are in the software and verified, not intentions:

  • patient files are encrypted with AES-256-GCM, with a separate key per clinic;
  • identifying fields — social security number, phone, mobile, email — are encrypted in the database and can be searched only through a keyed index, so the plain values are not stored in it;
  • every file access and every change is written to an audit log, with the values themselves redacted;
  • permissions are per role, and a clinic grants only the roles it intends to;
  • backups are encrypted with a separate key, and restoring one is verified;
  • traffic is encrypted with TLS, and one clinic cannot see another's data;
  • access to production data is limited to the people who operate the service, and development runs on data that is not real.

2.8 Your rights

If you are a patient, your request goes to the clinic that holds your record: it is the controller and it decides, and we help it answer. If you have an account with us, or you have written to us, you may ask us for a copy of your data, for a correction, for deletion, for a restriction, or object to a processing; you may take your data elsewhere; and where a processing rests on consent, you may withdraw it at any time.

We answer within a month. If you are not satisfied, you may complain to the Hellenic Data Protection Authority — and you do not have to come to us first.

2.9 Children

Records of minors are part of a patient's record and are held by the clinic on the same terms as any other record. We do not create accounts for children, and we do not process their data for any purpose of our own.

2.10 Changes to this policy

When this policy changes in a way that matters, we tell account holders by email, and the version on this page changes with it.

3. Cookie Policy

Two kinds of cookie: the ones the application needs, and statistics that you may refuse.

3.1 The ones the service needs

These are set whatever you choose, because without them there is no signed-in session and no working form:

  • a session cookie, which is what keeps you signed in;
  • a token that protects every form against cross-site request forgery;
  • a cookie that remembers the language you chose;
  • a setting in your browser that remembers the light or dark theme;
  • a note in your browser that remembers your answer to this banner.

3.2 Statistics, only with your consent

The public pages — this website, the blog, a clinic's booking page — count their visits with Google Analytics. It is loaded only after you accept it in the banner: before that, no request reaches Google and no cookie is set.

If you refuse, the site works exactly as it does otherwise, and nothing about you is recorded. You can change your mind whenever you like with the cookie settings button below.

3.3 No advertising

We set no advertising or marketing cookies, we build no profiles, and we sell nothing about you to anyone. There is no social media pixel on these pages.

3.4 In your browser

Every browser lets you see, block and delete cookies. Blocking the session cookie will sign you out and stop you signing in; that is the only consequence worth knowing about here.

4. Data Processing Agreement

What we commit to for the patient data in a clinic's account, as Article 28 GDPR requires.

4.1 The agreement

For the patient data in a clinic's account, the clinic is the controller and we are the processor. Accepting the terms also concludes a data processing agreement on the terms in this section, which is what Article 28(3) GDPR requires of the parties.

A copy in writing, countersigned, is available on request.

4.2 What we commit to

For as long as we process the clinic's patient data, we will:

  • process it only on the clinic's documented instructions — the service itself and these terms — and say so if an instruction would break the law;
  • keep everyone who can reach it under an obligation of confidentiality;
  • apply the security measures described above, and review them as the service changes;
  • use only the sub-processors listed below, tell the clinic before adding another, and give it the chance to object;
  • help the clinic answer its patients' requests to access, correct, delete or export their data;
  • tell the clinic without undue delay when a personal data breach affects its data, so it can meet its own deadline of 72 hours;
  • delete or return the data when the agreement ends, according to the retention schedule above;
  • give the clinic the information it needs to show that it complies, and allow an audit, under confidentiality;
  • not transfer patient data outside the European Economic Area.

4.3 Sub-processors

Only these, and only for this:

  • Hetzner — hosting, database and encrypted backups — Germany;
  • Scaleway — AI inference, on the messages that reach it — France;
  • ZeptoMail — transactional email, on a European endpoint — European Union;
  • Elorus — electronic invoicing, for the invoices the clinic is charged — Greece;
  • Stripe — card payments and billing — Ireland;
  • Google — statistics for the public pages, and only with consent — United States, under the EU–US Data Privacy Framework.

4.4 What the clinic commits to

The clinic is the controller, and it keeps that side of the bargain: it decides what is recorded and has a lawful basis for it, it informs its patients, it gives them a way to exercise their rights, and it instructs us only in ways that are lawful.

Anything here that you want explained, or in writing, or signed: [email protected].