1. Data Controller
HeyDottore holds a dual role under the GDPR:
- Data Processor (Art. 28 GDPR) for health data processed within the consultation and the delivery of messages and documents to people who do not yet have an account (section 12) — the Controller is the treating Doctor, a professional bound by professional secrecy, who processes the data for healthcare purposes under Art. 9(2)(h) GDPR. HeyDottore processes this data on their behalf under the signed DPA.
- Independent Data Controller (Art. 4(7) GDPR) for account, security, navigation and billing data and, based on your consent, for storing the health data you enter in your profile and consultation requests and making it available to the doctors you choose (section 4).
HeyDottore S.r.l.
Via Mario Pagano 63, 20145 Milano (MI)
P.IVA: 14781390969
Email: privacy@heydottore.com
Referente privacy: privacy@heydottore.com
2. Data Collected
Identification data:
- First and last name
- Email address
- Phone number (number verification, two-factor authentication and delivery notices)
- Date of birth
- Tax code (optional)
- Home address (optional)
Health data (special categories):
- Symptoms described by User
- Shared clinical history
- Uploaded reports and documents
- Messages exchanged with Doctors
- Prescriptions received
- Messages and documents your doctor delivers to you, even before you have an account (section 12)
Advanced Data Protection
Data is protected by encryption in transit (TLS) and encryption at rest at the infrastructure level (AES-256) provided by our EU cloud providers.
3. Purpose of Processing
- Provision of technical communication infrastructure between doctor and patient (as technological intermediary)
- Delivery, protection and temporary safekeeping of the messages and documents your treating doctor delivers to you, even before you have an account, on the doctor's behalf (section 12)
- User account management
- Payment processing
- Service-related communications
- Legal compliance
- Service improvement: platform usage analysis (which features are used and where a journey is interrupted), recorded as events linked to your account. Events contain only the action name and minimal technical data: never the content of messages, documents or health data
HeyDottore acts as Controller for platform data and, with your consent, for storing the health data you enter in your profile and requests (section 4); it acts as Processor for health data processed in the consultation, on behalf of the treating Doctor, in accordance with the DPA signed under Art. 28 GDPR. It does not provide healthcare services and is not part of the doctor-patient relationship.
4. Legal Basis
| Processing | Legal Basis |
|---|---|
| Service provision | Contract |
| Health data within the consultation | Healthcare purposes (Art. 9(2)(h) GDPR) — Controller: the treating Doctor |
| Storage of the health data you enter in your profile and consultation requests, and making it available to the doctors you choose to consult | Explicit consent (Art. 9(2)(a) GDPR) — Controller: HeyDottore. From when the doctor takes on the consultation: healthcare purposes (Art. 9(2)(h) GDPR) — Controller: the Doctor |
| Delivery of messages and documents to people without an account | Healthcare purposes (Art. 9(2)(h) GDPR) — Controller: the treating Doctor. For keeping the documents in your area after you create your access: your explicit agreement given at that moment (section 12) |
| Legal obligations | Legal obligation |
| Platform security, abuse prevention and access logs | Legitimate interest (Art. 6(1)(f) GDPR) |
| Service improvement | Legitimate interest |
| Invitation to a professional not yet registered, at a user's request | Legitimate interest (Art. 6(1)(f) GDPR) — at most two messages per contact, permanent one-click objection |
| How a new user reached us (referral code, campaign) | Legitimate interest |
5. Data Retention
| Data type | Period |
|---|---|
| Account data | Until you close your account: we then delete the account, contact details, sessions, preferences and files uploaded to your profile (section 8) |
| Records of consultations a doctor has taken on (messages, attachments, prescriptions, certificates, referrals) | Stay with the Doctor, who is their controller and keeps them to meet legal obligations, even after you close your account (Art. 17(3)(b) and (e) GDPR); HeyDottore keeps them on the Doctor's behalf. To ask for their deletion, contact the Doctor. Consultations no doctor has taken on are deleted with the account |
| Tax documents (invoices and receipts) | 10 years (Art. 2220 Italian Civil Code) |
| Messages and documents of a delivery received without an account | Viewable from the link for 30 days after the last delivery; if you do not create your access, deleted within 90 days after the last delivery. A delivery receipt (dates, events and contact details used) is kept on the doctor's behalf, without the text of the messages or the attachments (section 12) |
| Security logs (logins, login attempts, sensitive operations) | Up to 10 years, in tamper-protected form, for platform security and for establishing or defending legal claims |
| Technical logs of emails and SMS sent (recipient, subject, date and outcome) | Up to 10 years, to prove that communications were sent and to handle any disputes |
| Platform usage events | 12 months, then automatically deleted. Removed earlier if you delete your account |
| Consents | Retained as proof of consent given (Art. 7 GDPR), also after you close your account |
| Contact details of an invited professional not yet registered | Never in clear text; encrypted for 8 days (the time for a single reminder), then only a cryptographic fingerprint. The invitation record is deleted after 180 days; an objection is kept forever (Art. 21 and 17(3)(b) GDPR) |
| Referral code stored in the browser | 90 days on your device, then deleted automatically |
6. Data Recipients
Your data is disclosed exclusively to the recipients listed below, appointed as data processors under Art. 28 GDPR where applicable:
| Recipient | Function | Processing country | Health data | Transfer safeguard |
|---|---|---|---|---|
| Supabase Inc. | Database (account, profile, consultations and messages) and storage of chat files (attachments and voice notes), documents signed by the doctor (prescriptions, certificates, referrals) and delivery attachments | EU (Frankfurt); US company | Yes | Standard Contractual Clauses (SCC) |
| Encore (Encore Cloud) | Application hosting, storage of documents attached to a consultation request or uploaded to a profile, profile photos and data exports, and technical logs | EU (euw1 region); the scheduler for periodic tasks runs in the USA, without personal data | Yes, including at rest | No non-EU transfer of stored data |
| Stripe, Inc. | Payments: collection on the doctor's behalf, refunds and transfers to doctors. For doctors only, identity verification (Stripe Identity: ID document and biometric face match, with explicit consent, Art. 9(2)(a) GDPR) | USA/EU | No: name, email and amount; the payment description names the doctor and may therefore reveal a care relationship. Biometric data only for doctor verification | EU-US Data Privacy Framework certified |
| Twilio Inc. | SMS (phone verification, two-factor authentication and delivery notices) | USA | No (phone number; a delivery notice may reveal a care relationship, see section 12) | EU-US Data Privacy Framework certified |
| Cloudflare, Inc. | Content delivery and traffic protection in front of our servers, anti-bot check (Turnstile) and cookieless aggregate web-page statistics (Web Analytics) | USA / global network | Yes, in transit only: traffic passes through its servers, which protect it | EU-US Data Privacy Framework certified |
| Resend | Transactional email (service notices, receipts, delivery emails and links to create your access) | USA | To a limited extent: emails do not contain the text of messages or documents, but they may name the doctor and may therefore reveal a care relationship; some notices include short texts written by the doctor, for example the reason for not accepting a request (see also section 12) | Standard Contractual Clauses (SCC) |
| Apple Inc. (Apple Push Notification service) | Push notifications on iOS devices | USA | No: notifications do not contain the text of messages; the title may show the name of the sender or doctor, which may reveal a care relationship | EU-US Data Privacy Framework certified |
| Functional Software, Inc. (Sentry) | Technical error monitoring for the web app | EU (Germany); US company | No: technical error messages and the page address, stripped of account identifiers, email addresses and access codes; it does not deliberately collect message content | Standard Contractual Clauses (SCC) |
| Google LLC (Firebase App Check) | Integrity check of the iOS app | USA | No (technical app and device identifier, IP address) | EU-US Data Privacy Framework certified |
| Aruba (Electronic Invoicing) | Sending HeyDottore's invoices to doctors through the Italian e-invoicing exchange system (SdI) | Italy | No (doctors' billing data only) | No non-EU transfer |
In addition, your data is disclosed to:
- The platform Doctors you choose for your consultations — independent controllers of the care data processing
- HeyDottore's tax adviser (accountant), for bookkeeping and tax compliance: receives billing data
- Competent authorities, if required by law
We NEVER sell your data to third parties for commercial or advertising purposes.
6-bis. Professional Credentials Verification (FNOMCEO)
Before activating a doctor's profile, a person on the HeyDottore team checks that the doctor is enrolled in the Register of Physicians, Surgeons and Dentists, by consulting the public register of their provincial Medical Council or the national FNOMCeO register (portale.fnomceo.it). They compare the first and last name, date of birth and registration number given by the doctor with the published ones and check that the registration is active.
- Legal basis: performance of the contract with the doctor (Art. 6(1)(b) GDPR), because the Terms for doctors provide for this check before activation; legitimate interest in protecting patients and defending legal claims (Art. 6(1)(f) GDPR).
- When: at the doctor's registration, before the profile is activated. The check may be repeated later, for example after a report.
- Data processed: the doctor's identification and register data, already public by law (DPR 221/1950).
- Data retained: the outcome of the check, with the date, the register consulted and the person who carried it out and, if captured, an image of the register page with its cryptographic fingerprint. They are protected against modification and kept for up to 10 years, to prove the check and defend legal claims.
- No consent required: the check is necessary for the contract and is not based on consent.
7. Non-EU Transfers
Health data is stored on servers within the European Union. However, some of our providers are US companies or process data in the United States. For each of them, the transfer is covered by one of the following safeguards under Chapter V of the GDPR:
- EU-US Data Privacy Framework (DPF) certification: Stripe, Inc.; Twilio Inc.; Cloudflare, Inc.; Apple Inc.; Google LLC (Firebase App Check).
- Standard Contractual Clauses (SCC) approved by the European Commission: Supabase Inc. and Functional Software, Inc. (Sentry), which store data in the EU but are US companies; Resend, which processes data in the USA.
Health data stored by Supabase and Encore remains hosted in the EU region; Encore uses only its scheduler for periodic tasks in the USA, which receives no personal data.
You can request a copy of the safeguards applied by writing to privacy@heydottore.com.
8. Data Subject Rights
Under GDPR, you have the right to:
- Access your data
- Rectify inaccurate data
- Delete your data
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent at any time
- Lodge a complaint with the Data Protection Authority
You can lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it). Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal (Art. 7(3) GDPR).
Contact: privacy@heydottore.com
Closing your account and erasure (Art. 17 GDPR). You can close your account from your privacy settings or by writing to privacy@heydottore.com. We delete the data HeyDottore controls: account and contact details, sessions, preferences, usage events, files uploaded to your profile and consultations no doctor has taken on. We also delete messages and documents received through a delivery (section 12): the doctor keeps only a receipt, with dates and status. The records of consultations a doctor has taken on (because they accepted the request, wrote to you or replied, or issued a document) stay with the doctor instead, who is their controller and must keep them by law: we tell the doctor you have closed your account and, if you want those records deleted too, you need to contact the doctor. Receipts and invoices are also kept, to meet tax obligations, as is the proof of the consents you gave (Art. 7 GDPR). Before closing your account you can download a copy of your data.
If you received a delivery from your doctor and do not have an account, you can exercise your rights by contacting your doctor, who is the controller, or by writing to privacy@heydottore.com: we forward the request to your doctor and assist them in handling it (section 12).
9. Minors
Accounts are reserved for people aged 18 or over. At registration, including when you create your access from a delivery received from your doctor, your date of birth is requested to verify this requirement; if we become aware that an account was created by a minor under 18, we will delete it. A parent or legal guardian may, however, ask a doctor from their own account for a consultation concerning a minor. In that case you enter the minor's data, including health data, and you give the consents provided for in this notice as parent or guardian, on the minor's behalf. As for any consultation, once the doctor takes it on, the doctor processes the data as controller and HeyDottore on the doctor's behalf (section 4). You exercise the rights in section 8 over the minor's data.
10. Security
- Encryption in transit (TLS) and at rest at the infrastructure level
- Two-factor authentication mandatory for HeyDottore staff and for doctors who have verified their phone number; available to patients
- Daily database backups, kept for 7 days
- Logs of logins and sensitive operations, protected against modification
- Limits on login attempts and anti-bot protection
- Periodic security reviews of the code and configuration
11. Updates
This policy may be updated periodically. Significant changes will be communicated via email at least 15 days before taking effect. This policy is drafted in Italian; the English version is a courtesy translation and, in case of discrepancy, the Italian text prevails.
12. Delivery of messages and documents to people without an account
Your doctor can deliver health messages and documents to you through HeyDottore even before you have an account: you receive a link by SMS, by email or directly from the doctor. This is the privacy notice for people who receive a delivery (Art. 14 GDPR).
Who processes your data. The data controller is your doctor. HeyDottore S.r.l. acts as data processor, on the doctor's behalf and instructions (Art. 28 GDPR).
Which data, and where it comes from. Name, phone number and, if any, email address were provided by your doctor; the messages and documents are the ones your doctor chose to deliver to you. The platform also records the technical data needed to keep the delivery secure (openings, number verifications, device used).
What you see without an account. The text of the message can be read from the link you received. To open the attached documents you need to create your access, or link them to the one you already have.
Why. Solely to deliver what your doctor sends you, protect access to it and keep it for the stated period. Legal basis: your doctor's healthcare purposes (Art. 9(2)(h) GDPR); for keeping the documents in your area after you create your access, your explicit agreement given at that moment.
How long. The contents can be viewed from the link for 30 days after the last delivery. If you do not create your access, they are permanently deleted within 90 days after the last delivery. Once you create your access, they stay in your area as long as your doctor uses HeyDottore: if the doctor closes their account, the documents they delivered to you are deleted from your area too. If you want to keep them long term, download them or ask your doctor for a copy.
Who receives them. Only the technical providers needed for delivery (SMS: Twilio; email: Resend), appointed as sub-processors (section 6). Delivery SMS and emails contain neither the message nor the type of document, but they may reveal that you are in care with that doctor. No commercial use, no disclosure to third parties.
Our messages. HeyDottore writes to you only about the delivery: the message with the link, verification codes, the link to create your access when you ask for it, and a single reminder before the documents expire. None of our SMS will ever ask you to share codes or data: you enter codes only yourself, on our pages.
Your rights. You can at any time obtain the deletion of your data and stop further deliveries, and exercise all rights under Arts. 15–22 GDPR, by contacting your doctor, who is the controller, or by writing to privacy@heydottore.com: in that case we forward the request to your doctor and assist them in handling it. You will receive a reply within one month. If the message is not for you, you can deactivate the link from the page itself. You have the right to lodge a complaint with the Italian Data Protection Authority (Garante).
13. If you are a doctor
This section is the privacy notice for doctors who use HeyDottore (Art. 13 GDPR). It covers your data as a professional and as a user of the Platform, for which HeyDottore S.r.l. is the controller. For your patients' health data, you are the controller: HeyDottore processes it on your behalf, as processor, under the DPA and the Terms for doctors.
Which data we process.
- Registration and profile: first and last name, title, email, phone, date of birth, specialty and training, photo and presentation, the practices and contact details you choose to publish, fees and availability.
- Medical register: Medical Council and registration number, and the outcome of the check on the public register (section 6-bis).
- Identity verification with Stripe Identity, only if you are asked to do it: we keep the outcome, the name shown on the document, the type, country and expiry of the document and whether the date of birth matches the one you gave. The document images and the biometric face comparison stay with Stripe.
- Tax and billing data: tax code, VAT number, tax regime, billing address, recipient code or certified email (PEC), your signature of the collection mandate (date, text version, IP address and device), the amounts collected on your behalf and transferred, and the invoices HeyDottore issues to you.
- Data for receiving payouts: bank details and the required documents are collected directly by Stripe (Stripe Connect), as an independent controller. HeyDottore receives the account status and the name (and, if available, the date of birth) verified by Stripe, to check that they match your registration.
- Declarations and acceptances: Terms, specific approval of clauses, professional liability insurance declaration, relationship with the Italian National Health Service, DPA, with date and text version.
- Communications with us: emails, SMS, notifications and support messages.
- Use of the service: profile activation and usage events, requests left to expire and automatic pauses (Terms for doctors, clause 7.2), reports received, internal notes and flags by our team, suspensions and their reasons.
- Referral: the presentation code you registered with, if any.
- Security: logins, devices and logs of sensitive operations.
Why, and on what legal basis.
- Contract (Art. 6(1)(b) GDPR): creating and managing your account; checking your registration before activating your profile; showing your profile to patients; managing consultations, subscriptions, collections on your behalf and transfers (collection mandate); support and service communications; automatic pause of requests and suspensions provided for in the Terms.
- Legal obligations (Art. 6(1)(c) GDPR): invoicing, bookkeeping and retention of tax documents; requests from authorities.
- Legitimate interest (Art. 6(1)(f) GDPR): security of the Platform and prevention of fraud and abuse, including comparing your registration data with the data verified by Stripe; protecting patients, through the handling of reports and internal notes; improving the activation process; managing agreements with whoever referred you; establishing, exercising or defending legal claims. You can object at any time, on grounds relating to your particular situation (Art. 21 GDPR).
- Explicit consent (Art. 9(2)(a) GDPR): only for the biometric face comparison of Stripe Identity, if you are asked to do it. You can withdraw it at any time, without affecting checks already carried out.
How long.
- Account, profile (including the outcome of the identity verification), communications and usage data: for the duration of the relationship. When the account is closed (Terms for doctors, clause 7.4) we delete them, except as set out below; usage events are deleted after 12 months in any case.
- Invoices, tax data and collection mandate: 10 years (Art. 2220 Italian Civil Code).
- Outcome of the register check: up to 10 years (section 6-bis).
- Declarations and acceptances: kept as proof, also after the account is closed (Art. 7 GDPR).
- Security logs and communication delivery logs: up to 10 years (section 5).
Who we share them with.
- Patients and visitors of your public profile: the data you choose to publish (name and title, photo, specialty, Medical Council and registration number, practices, contact details and fees).
- Patients who pay for a consultation or a subscription: name, title, Medical Council and registration number in the summary before payment and, in the tax documents issued on your behalf, the data required by law.
- The providers in section 6, for the same functions: in particular Stripe, for collections, transfers and identity verification.
- HeyDottore's tax adviser (accountant), for bookkeeping and tax compliance.
- The Italian Revenue Agency, through the Exchange System (SdI), for electronic invoices.
- Whoever referred you, if you registered with a presentation code: a summary with your name, specialty, start date, activation stage and whether you are active. Never amounts or your patients’ data.
- WhatsApp Ireland Limited, if we contact you on WhatsApp at the number you gave us to help you activate your profile. If you prefer not to be contacted on WhatsApp, just tell us.
- Competent authorities, where required by law.
Your rights. You have the rights in section 8: access, rectification, erasure, restriction, portability, objection, withdrawal of consent and complaint to the Italian Data Protection Authority (Garante). You can correct most of your data yourself in your profile; for the rest, write to privacy@heydottore.com. We cannot delete data the law requires us to keep (for example invoices), nor data needed to defend a legal claim, for as long as it is needed. For your patients’ requests about consultation data, which you control, we assist you as provided in the DPA.