Privacy Policy
Last updated: 01/01/2025
This Privacy Policy explains how Dr Izabela Saftei (“we”, “us”, “our”) collects, uses, and protects your personal data when you visit dr-ima.com, book an appointment, or receive treatment.
1. Who We Are
Dr Izabela Saftei
Email: dr.asafteizabela@gmail.com
2. The Data We Collect
- Identity & Contact: name, date of birth, email, phone.
- Medical & Consultation: health history, photos (with consent), contraindications, treatment notes.
- Booking & Payment: appointment details, transaction references (we do not store full card details).
- Website Usage: IP address, device info, cookies/analytics (see Cookie Policy).
- Marketing Preferences: opt-in choices for email/SMS.
3. How We Use Your Data (Lawful Bases)
- Provide clinical services (consultation, treatment, aftercare) — performance of a contract.
- Medical records & safety — legal obligation and legitimate interests; special category data processed under healthcare basis.
- Appointments & reminders — performance of a contract / legitimate interests.
- Payments & invoicing — performance of a contract / legal obligation.
- Marketing communications — consent (you can opt out anytime).
- Site analytics & improvement — consent (non-essential cookies).
4. Sharing Your Data
We only share what’s necessary with trusted parties:
- Booking & scheduling tools (e.g., Amelia) to manage appointments.
- Payment processors for secure transactions.
- Clinical referrals (with your consent) where appropriate.
- IT/hosting providers for secure operation of our website and systems.
- Regulators or legal authorities where required by law.
5. International Transfers
Some providers may process data outside the UK/EEA. Where this occurs, we rely on adequacy regulations or Standard Contractual Clauses and additional safeguards.
6. Data Retention
We keep records only as long as necessary: clinical records in line with healthcare guidance/legal duties; booking/financial records per tax and accounting rules; marketing data until you opt out or your consent expires.
7. Your Rights
- Access, rectify, or erase your data.
- Restrict or object to processing.
- Data portability (where applicable).
- Withdraw consent at any time for marketing or photos.
- Complain to the ICO (UK) or your local authority.
To exercise your rights, contact: dr.asafteizabela@gmail.com.
8. Security
We use appropriate technical and organisational measures to protect your personal data, including secure hosting, access controls, and staff training.
9. Children
Our services are for adults (18+). We do not knowingly collect data from minors.
10. Changes
We may update this policy to reflect changes in law or practice. Any material updates will be posted here with a new “Last updated” date.
