Skip to main content

Privacy Policy

Last updated: October 08, 2025

1. General Provisions

This Privacy Policy defines the procedure for processing and protecting personal data of users of the Odesa Regional Clinical Hospital website (hereinafter referred to as the "Site").

By using the Site, you agree to the terms of this Privacy Policy and consent to the processing of your personal data.

2. Data Controller

Data Controller: Orel Konstantin Sergeevich
Address: 26/32 Akademika Zabolotnoho St, Odesa
Email: [email protected]
Phone: +38 (073) 333-54-24

3. What Data We Collect

We may collect the following categories of personal data:

  • Contact Information: first name, last name, phone number, email address
  • Medical Information: complaints, symptoms, duration of illness (upon your voluntary provision)
  • Technical Data: IP address, browser type, operating system, site visit data
  • Cookies: cookie files to improve site functionality

4. Purpose of Data Processing

We process your personal data for the following purposes:

  • Appointment booking with the doctor
  • Communication with you to confirm or change appointments
  • Providing medical consultations
  • Improving the quality of our services
  • Analyzing site traffic and user behavior (anonymously)
  • Compliance with legal requirements

5. Legal Basis for Processing

Personal data processing is carried out based on:

  • Your consent (Art. 6(1)(a) GDPR) — when filling out forms on the site
  • Contract performance (Art. 6(1)(b) GDPR) — to provide medical services
  • Legitimate interests (Art. 6(1)(f) GDPR) — for analytics and site security

6. Data Retention Period

We retain your personal data for:

  • Patient data: 5 years from the last visit (in accordance with Ukrainian medical legislation)
  • Technical data and cookies: up to 12 months
  • Marketing data: until consent withdrawal or 2 years from last interaction

7. Data Transfer to Third Parties

We do not transfer your personal data to third parties, except for:

  • Analytics services: Google Analytics (anonymous visit data)
  • Hosting providers: to ensure site operation
  • Government authorities: upon lawful request

All third parties are obliged to comply with GDPR requirements and ensure an adequate level of data protection.

8. Cookies and Tracking Technologies

We use cookies for:

  • Necessary cookies: ensuring site functionality (language, settings)
  • Analytics cookies: Google Analytics for visit statistics (only with your consent)

You can manage cookies through your browser settings or through our cookie consent banner.

9. Your Rights

Under GDPR, you have the following rights:

  • Right of access: obtain a copy of your personal data
  • Right to rectification: correct inaccurate data
  • Right to erasure: "right to be forgotten"
  • Right to restriction of processing: limit the use of your data
  • Right to data portability: obtain data in a structured format
  • Right to object: object to data processing
  • Right to withdraw consent: at any time

To exercise your rights, please contact us: [email protected]

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, loss, or disclosure:

  • SSL/TLS encryption for data transmission
  • Secure servers and regular software updates
  • Limited access to personal data
  • Regular security audits

11. International Data Transfers

Your data is stored on servers located in the European Union. If data is transferred outside the EU, we ensure an adequate level of protection in accordance with GDPR requirements.

12. Changes to Privacy Policy

We reserve the right to make changes to this Privacy Policy. All changes will be published on this page with an updated date.

13. Contact and Complaints

If you have questions about the processing of your personal data or wish to exercise your rights, please contact us:

Email: [email protected]
Phone: +38 (073) 333-54-24
Address: 26/32 Akademika Zabolotnoho St, Odesa

You also have the right to lodge a complaint with the supervisory authority for data protection issues in your country.