GDPR
Privacy notice
Last updated on 19 June 2026. This notice explains how OsteoCure processes personal data in the booking portal and practice management software. The practice owner or DPO must validate the final legal wording before the system is used with real patient data.
Controller: OsteoCure practice. Contact for privacy questions: [email protected].
What data do we process?
- Identification and contact details such as name, email address, phone number and account details.
- Appointment data such as treatment type, time, practitioner, room, status and appointment communication.
- Health data and consultation information such as intake answers, medical history, treatment notes, body-map annotations, attachments, reports and follow-up.
- Administrative data such as invoices, payment statuses, audit-log data and technical security information.
Why do we process this data?
- To schedule, confirm, change and follow up appointments.
- To maintain a careful patient record for human patients and animal profiles.
- To manage consultations, reports, exercises, invoices, reminders and customer communication.
- To keep the application secure, restrict access by role and investigate misuse or mistakes through audit logs.
Legal basis and health data
- For ordinary personal data, processing relies on performance of care or services, legal obligations, legitimate interest for security and administration, or consent where appropriate.
- Health data is a special category of personal data. In addition to an Art. 6 legal basis, the practice must document an appropriate Art. 9 condition, for example explicit consent or necessity in the context of health care. The final wording must be validated by the practice owner or DPO.
- Consent for non-essential communication, such as rebooking reminders, can be withdrawn via the unsubscribe link or through the practice.
Retention periods
- Medical records are kept for as long as necessary or legally required for continuity of care, liability and statutory retention duties. In this production version, the starting point for medical records is 30 years unless the practice or DPO formally sets a different period.
- Invoices and accounting data are retained according to the applicable tax retention duties.
- Audit logs are kept as long as needed for security, accountability and legal justification. They do not contain free medical content.
Recipients and processors
- Data is accessible to authorised roles within the practice, such as therapist, receptionist or administrator, according to the least-privilege principle.
- The application uses processors for hosting, storage, security, email, video, calendar connections and technical support. Processor agreements, regional settings and transfer mechanisms must remain documented for production.
- Medical data is not sold and is not used for advertising tracking.
Appointment reminders by email or WhatsApp
- During registration you choose yourself whether you want to receive appointment reminders by email and/or via WhatsApp. This choice is optional and you can change or withdraw it at any time via "My account" in the customer portal or through the practice.
- If you choose WhatsApp, your phone number and limited appointment details (date, time and practice name) are processed via WhatsApp. WhatsApp is provided by Meta Platforms; messages travel through Meta's infrastructure, which may involve a transfer outside the European Economic Area. The legal basis for this is your explicit consent.
- The WhatsApp reminder deliberately does NOT contain a treatment type or other health data (data minimisation). If you withdraw your consent, no further WhatsApp reminders are sent.
Rights of data subjects
- You may request access, correction, portability, restriction or objection where the GDPR provides these rights.
- In the customer portal, you can request a data export and submit an erasure or pseudonymisation request. Some data cannot be fully erased where statutory retention duties or medical-record obligations apply; in that case, identifying data is pseudonymised where possible.
- Requests can be sent to [email protected]. The practice handles requests within the legal deadlines.
Security
- OsteoCure uses role-based access, secure session cookies, audit logs, direct object storage for attachments, encryption for sensitive tokens and security headers.
- Access to production environments, backups and processor accounts must be operationally limited and periodically reviewed.