Privacy Policy
Last updated: 25 July 2026
1. Who we are
The SaniOra platform is operated by IRIMIA D.A. CRISTINA PERSOANĂ FIZICĂ AUTORIZATĂ, with its professional office at Bucharest, District 1, 136 Bucureștii Noi Boulevard, ground floor, apt. 5, postal code 012366, Romania, registered with the Trade Register under no. F2026036397008, Unique Registration Code 55259127 and European Unique Identifier (EUID) ROONRC.F2026036397008, hereinafter referred to as the “Controller”, “we” or “SaniOra”.
For questions about personal data processing, contact us at cristina@saniora.ro or by post at the professional office above.
2. Scope of this policy
This Privacy Policy explains how we collect, use, store, disclose and protect personal data processed through SaniOra, available at https://saniora.ro/medical/.
It applies to all platform users, including healthcare providers, patients, relatives or carers, representatives of organisations and anyone interacting with the website, forms, user accounts or communication features.
3. Legal framework
Personal data is processed in accordance with Regulation (EU) 2016/679 (“GDPR”), Romanian Laws no. 190/2018 and no. 506/2004, and other applicable rules on data protection, electronic communications, information security and contractual relations.
4. Categories of personal data we may process
Depending on how you use the platform, we may process:
- identification data: first and last name, organisation name, account type, position or declared role;
- contact data: email, telephone number, address, county/region, locality and other contact details you provide;
- authentication and account administration data: hashed password, language preferences, account status, technical logs and security information;
- data entered in profiles, listings, forms or messages;
- data about relationships between users, including contact-data access requests, approvals, refusals and correspondence history;
- technical data about use of the website, device, browser, session and preferences stored through cookies or similar technologies;
- any other data you choose to send us directly.
Information about health, medical needs or requested care may constitute sensitive or special-category data. We process it only as necessary to operate the platform and under the conditions required by law.
5. Sources of data
We collect personal data:
- directly from you when you complete forms, create an account, publish listings, send messages or contact us;
- automatically through the website, cookies and technical platform functions;
- indirectly from other users when they lawfully enter data needed to use the platform, for example for requests, contractual relationships or authorised representation.
6. Purposes and legal bases
We may process your data for the following purposes and legal bases:
- creating and administering user accounts – Article 6(1)(b) GDPR, performance of a contract or pre-contractual steps;
- technical operation, authentication, security and abuse prevention – Article 6(1)(f) GDPR, legitimate interests;
- managing listings, profiles, messages and requests for access to contact data – Article 6(1)(b) and/or (f) GDPR;
- compliance with legal obligations – Article 6(1)(c) GDPR;
- handling requests, complaints and correspondence – Article 6(1)(b), (c) or (f) GDPR, as applicable;
- analysis, audit, legal claims and dispute management – Article 6(1)(f) GDPR;
- administrative notices and communications – Article 6(1)(b), (c) or (f) GDPR;
- processing health or medical-needs data – where applicable, under the special grounds in Article 9 GDPR and relevant national law, together with the purpose of the feature used.
Where consent is required, it will be requested separately. Refusing consent may make certain features unavailable where they legitimately depend on that processing.
7. Why we process health or care-related data
Some features may involve medical needs, requested care, healthcare professions, health services or other sensitive information. This data is processed strictly to facilitate interactions between users and operate the platform, within applicable technical and legal limits.
Users should provide only what is strictly necessary and avoid excessive or irrelevant medical information in public or semi-public fields.
Applicable details and statements are set out in the Health data information and consent.
8. How long we retain data
We retain personal data only as long as needed for the purposes for which it was collected, legal compliance, defending our rights, or legitimate security and audit requirements.
The following periods and criteria apply:
- account, profile and medical information is retained while the account exists and deleted from the active database when the user deletes the account, except for separate records retained for the audit, security, abuse-prevention or legal periods below;
- messages and contact requests are retained for no more than 24 months from the creation of each record and deleted earlier if the user deletes the account;
- login and registration events used for security and abuse prevention are retained for 14 days;
- contact data strictly needed to prevent abusive reuse after deletion of a provider account is retained for 180 days;
- account and administrative-operation audit records are retained for no more than 3 years from the event;
- financial and accounting documents, when generated, are retained for 5 years calculated from 1 July of the year following the financial year in which they were prepared, or another period required by a specific applicable law;
- automatic database backups are rotated for no more than 30 days. Deleted active-system data may remain in backups during this period without being reused for other purposes. Manual copies made before migrations or technical work are kept separately only until the work is completed and verified, then securely removed.
Where required by law, a valid authority request or ongoing litigation, strictly necessary data may be kept for the required period or until final resolution. Data is then deleted or anonymised, as appropriate.
9. Who may receive data
Within necessary and proportionate limits, we may disclose personal data to:
- other platform users where a feature requires the interaction and there is appropriate approval or another lawful basis;
- technical, hosting, email, security, maintenance, software development, IT support or analytics providers acting as processors or independent recipients, as applicable;
- public authorities, courts, regulators or other competent bodies where required or permitted by law;
- consultants, auditors or lawyers where needed to protect the Controller’s rights and legitimate interests.
Certain individual free-text fields, including medical-service names, observations, medical or care needs, listing titles and content, reviews, messages and correspondence, are sent to OpenAI for automated analysis. Depending on the policy for each field, the analysis helps prevent offensive content, threats, harassment, inappropriate sexual content, publication or concealment of contact details and inappropriate disclosure of personal data. Medical-service names are checked only for inappropriate sexual content and concrete contact details; legitimate descriptions of diseases, diagnoses, symptoms, treatments, medicines and procedures are allowed. Structured profile fields are validated locally and are not intentionally sent to OpenAI, including names, organisation name, contact person, telephone, email, address, locality, postal code, coordinates, Romanian personal identification number (CNP), internal identifiers and authentication data. Each external analysis contains only the individual free text, a generic field type, language and a pseudonymised identifier, without other profile data, real database identifiers or conversation history. We request classification without reproduction of the text and disable storage for generative requests.
10. International data transfers
The platform’s main data is hosted on infrastructure in France, and the email service uses infrastructure in Romania. These operations take place in the European Economic Area.
Certain free texts, filtered and minimised as described in section 9, may be sent to OpenAI for automated analysis. The current configuration uses OpenAI’s global API and no confirmed contractual option for exclusive EU data residency. Processing may therefore involve transfers outside the European Economic Area, including to the United States of America.
OpenAI states that it uses adequacy decisions and European Commission-approved Standard Contractual Clauses, as applicable, for transfers to jurisdictions without an adequacy decision. Generative requests are sent with response storage disabled, but this setting is not a Zero Data Retention guarantee. According to the provider’s documentation, the standard configuration may include abuse-monitoring logs generally retained for up to 30 days, except where longer retention is legally required or needed to protect the services or third parties.
The platform does not intentionally send structured profile fields such as name, telephone, email, address, CNP, coordinates, authentication data or real database identifiers to OpenAI. Filtering and minimisation are applied before external calls. The Controller periodically reviews providers, processing locations and applicable legal mechanisms and will update this policy if infrastructure or transfer conditions change.
11. Data security
We implement reasonable technical and organisational measures against unauthorised access, loss, destruction, alteration or unlawful disclosure. These may include access controls, encryption, password hashing, logging, content filtering, backups, restricted internal access and contractual safeguards with providers.
No technical measure can guarantee absolute security. Users must use strong passwords, protect their credentials and avoid unnecessary disclosure of sensitive data.
12. Your rights
Subject to the GDPR, you may have the rights to:
- information; access; rectification; erasure (“right to be forgotten”), where applicable;
- restriction of processing; data portability, where applicable; and objection under the law;
- not be subject to a decision based solely on automated processing, including profiling, where applicable;
- withdraw consent where processing relies on consent, without affecting prior lawful processing;
- complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP);
- apply to the competent courts.
13. How to exercise your rights
Send requests to cristina@saniora.ro. Where necessary, we may reasonably request additional information to verify your identity.
We will respond within the statutory period, normally no later than one month after receipt, subject to a GDPR-compliant extension for complex or numerous requests.
14. Data entered about other people
If you enter another person’s data, you declare that you are legally entitled to provide it and that you have informed that person where required by law. You are responsible for the lawfulness of uploaded data and respect for data-subject rights.
15. Cookies and similar technologies
For details about cookies, legal bases, acceptance or refusal options and withdrawal mechanisms, see our separate Cookie Policy.
16. Changes to this policy
We may update this Privacy Policy to reflect legislative, technical, operational or commercial changes. The updated version and its last-updated date will be published on the website.
17. Contact
For questions about this policy or personal data processing on the platform, contact cristina@saniora.ro.