1. Who we are
Careline ("we", "us") facilitates access to healthcare professionals and coordinates medical appointment requests on behalf of patients and organizations. The data controller is [legal entity name, registration number, registered address].
2. Data we collect
We collect only the information needed to handle your request: identity (first name, last name), contact details (email, telephone), the city and country in which you are seeking care, the type of practitioner requested, your consultation preference, your preferred period and any information you choose to add.
We ask you not to include detailed medical information in free-text fields. Any health-related information you nevertheless provide is treated as sensitive data and processed only to route your request.
3. Purposes and legal bases
Handling and following up appointment requests (performance of a service you requested, and your explicit consent where health data is involved).
Responding to contact and partnership enquiries (our legitimate interest in replying to you).
Maintaining the security and integrity of the service (legitimate interest and legal obligations).
4. Recipients
Data may be shared with the healthcare professionals, practices or establishments needed to arrange your appointment, and with technical service providers acting on our instructions under contract. We do not sell personal data.
5. International transfers
Careline operates internationally. Where data is transferred outside your region, we apply appropriate safeguards required by the applicable regulations, such as standard contractual clauses.
6. Retention
Personal data is kept only for as long as necessary for the purposes described above and for the periods required by applicable law. Indicative retention periods must be confirmed per country: [to be completed].
7. Your rights
Depending on your jurisdiction, you may request access, rectification, erasure, restriction, portability, or object to certain processing, and withdraw your consent at any time. Contact us at [privacy contact email]. You may also lodge a complaint with your local supervisory authority.
8. Security
We apply technical and organizational measures adapted to the risk, including access control, encryption of data in transit and confidentiality obligations for staff. No claim of certification is made unless explicitly stated and held.
9. Contact
For any question about this policy, write to [privacy contact email].