DRAFT — not legal advice, not yet reviewed by a lawyer. Do not publish while this banner is present.

Privacy Policy

How Z2A Health collects, uses and protects your personal data — including your health data, which receives the strongest protection available under EU law.

Version 0.1 (draft) · Last updated [[DATE]] · Effective [[DATE]]

Before you read further

Every highlighted field below must be completed before this page goes live, and the whole document must be reviewed by a data protection lawyer qualified in EU and Moldovan law. Publishing an incomplete privacy notice for a service processing health data is itself a breach of GDPR Articles 12 and 13.

Contents
  1. Who we are
  2. What data we collect
  3. Why we use it, and our legal basis
  4. Your health data specifically
  5. Who we share it with
  6. Sending data to Moldova
  7. How long we keep it
  8. Your rights
  9. Security
  10. Cookies
  11. Children
  12. Changes to this policy
  13. Contact and complaints

1. Who we are

Z2A Health is a cross-border telemedicine platform that connects members of the Moldovan diaspora with doctors, clinics and hospitals in Moldova.

The data controller responsible for your personal data is:

Legal entity[[REGISTERED COMPANY NAME]]
Registration no.[[COMPANY NUMBER]]
Registered address[[FULL REGISTERED ADDRESS]]
Email[[privacy@z2ahealth.com]]
Data Protection Officer[[DPO NAME AND CONTACT]]
EU representative[[IF THE CONTROLLER IS ESTABLISHED OUTSIDE THE EU, AN ART. 27 REPRESENTATIVE IS MANDATORY]]

A DPO is not optional here

GDPR Article 37(1)(c) requires a Data Protection Officer where core activities consist of large-scale processing of special-category data. Health data on a telemedicine platform is exactly that. A Data Protection Impact Assessment under Article 35 is also mandatory and must be completed before processing begins, not afterwards.

Who is the controller of your consultation notes?

This needs care, because it is the question most telemedicine privacy policies get wrong. When a doctor writes clinical notes about you, that doctor — or the clinic employing them — is normally an independent controller of those notes under professional medical obligations, while Z2A Health is a controller for the account, booking and payment data and a processor for the clinical record. The exact split must be documented in a joint-controller or controller-to-processor arrangement under Article 26 or 28.

[[CONFIRM THE CONTROLLERSHIP SPLIT WITH COUNSEL AND STATE IT PLAINLY HERE]]

2. What data we collect

CategoryExamples
IdentityName, date of birth, country of residence, email address, password (stored only as a cryptographic hash, never in readable form)
Account activitySign-in times, IP address, browser and device type, language and currency preference, timezone
BookingWhich doctor, when, in which timezone, the reason you gave for the appointment, cancellations
Health dataSymptoms you describe, consultation notes written by your doctor, diagnoses, prescriptions, uploaded documents such as lab results and imaging, medication and allergy lists
Consultation mediaAudio and video of the consultation itself, where recording takes place — see section 4
PaymentAmount, currency, date, the last four digits of the card and its brand. We never see or store your full card number; that goes directly to our payment processor
SupportMessages you send us and our replies
Doctors onlyProfessional licence number, speciality, employing institution, malpractice insurance details, bank account for payouts, tax identification

Data we receive from third parties

If you sign in using Google, Facebook, LinkedIn or Apple, we receive your name, email address and profile picture from that provider. We do not receive your password and we do not gain access to your account there. We ask for the minimum scope needed to identify you.

3. Why we use it, and our legal basis

GDPR requires us to name a lawful basis for every purpose. Ours are:

PurposeLegal basis
Creating and running your accountArt. 6(1)(b) — performance of a contract with you
Arranging and delivering consultationsArt. 6(1)(b) contract, and for the health data within them Art. 9(2)(a) explicit consent together with Art. 9(2)(h) provision of health care
Taking payment and preventing fraudArt. 6(1)(b) contract, Art. 6(1)(c) legal obligation, Art. 6(1)(f) legitimate interests
Keeping records we are legally required to keepArt. 6(1)(c) legal obligation
Security, abuse prevention, audit loggingArt. 6(1)(f) legitimate interests in keeping a health platform secure
Service emails you cannot opt out of, such as booking confirmations and password resetsArt. 6(1)(b) contract
Marketing emailsArt. 6(1)(a) consent — separate, optional, and withdrawable at any time
Improving the platform using aggregated statisticsArt. 6(1)(f) legitimate interests, using data that no longer identifies you

We do not sell your personal data. We do not use your health data for advertising, and we do not use it to train machine learning models.

4. Your health data specifically

Health data is "special category" data under Article 9 and is prohibited from processing unless a specific exception applies. Two apply here, and both must hold:

Withdrawing consent stops future processing. It does not always delete past clinical records — see section 8, which explains this honestly rather than promising something we cannot deliver.

Recording of consultations

[[DECIDE AND STATE: ARE CONSULTATIONS RECORDED BY DEFAULT, ON REQUEST, OR NEVER?]]

If consultations are recorded, this section must state who can access the recording, how long it is kept, whether both parties must consent, and how to object. Several EU member states require the consent of every participant before a call may be recorded, and the rules are not uniform. Recording by default is the option most likely to create liability; recording only on explicit joint request is the safer design.

5. Who we share it with

We share your data only with those who need it to deliver the service:

RecipientWhat they receive and why
Your doctor and their clinicEverything relevant to your care. This is the point of the service.
Hosting provider
DigitalOcean, Frankfurt, Germany
Hosts the platform. Data is stored in the EU. [[CONFIRM DPA SIGNED]]
Video providerCarries the consultation call. [[NAME THE VENDOR, ITS DATA REGION AND WHETHER MEDIA IS END-TO-END ENCRYPTED]]
Payment processorProcesses your card payment. They receive your card details directly; we do not.
[[NAME THE PROCESSOR]]
Email providerDelivers service emails. Receives your email address and the message content, so we deliberately keep clinical detail out of emails. [[NAME THE PROVIDER]]
AuthoritiesWhere we are legally compelled, and only to the extent compelled.

A current list of sub-processors is maintained at [[URL]] and we will give notice before adding a new one.

6. Sending data to Moldova

This is the most legally significant section of this policy

The European Commission has not adopted an adequacy decision for the Republic of Moldova under GDPR Article 45. Moldova does not appear on the Commission's list of adequate third countries. This is not a formality — it means every transfer of your data from the EU to a doctor or clinic in Moldova requires a specific safeguard under Chapter V of the GDPR, and the platform cannot function without making such transfers.

If you are in the EU or EEA and consult a doctor in Moldova, your data leaves the EEA. We rely on:

Why we do not simply rely on your consent for the transfer

Article 49(1)(a) permits a transfer based on explicit consent, and it would be convenient to lean on that. But the European Data Protection Board's guidance is that Article 49 derogations must be occasional and non-repetitive. A platform whose entire purpose is routing consultations to Moldova makes these transfers systematically, so consent alone is not a defensible basis. Standard Contractual Clauses plus a transfer impact assessment is the correct mechanism, and it is work that must be done before launch, not after.

You can obtain a copy of the safeguards we use by writing to [[privacy@z2ahealth.com]].

Moldova is an EU candidate country and has been aligning its data protection law with the GDPR. Should the Commission adopt an adequacy decision, we will update this section.

7. How long we keep it

DataKept for
Account and profileWhile your account is open, then [[PERIOD]]
Clinical records and consultation notes[[THE MINIMUM RETENTION PERIOD FOR MEDICAL RECORDS UNDER MOLDOVAN LAW AND UNDER THE LAW OF THE PATIENT'S COUNTRY — THESE DIFFER AND THE LONGER USUALLY GOVERNS. CONFIRM WITH COUNSEL.]]
Payment and invoice recordsAs required by tax law, typically [[PERIOD]]
Security and audit logs[[PERIOD]]
Support correspondence[[PERIOD]]

8. Your rights

Under the GDPR you have the right to:

Erasure has a limit, and we would rather tell you now

If you ask us to delete everything, we can delete your account, your profile, your preferences and your marketing consents. We usually cannot delete the clinical record of a consultation that actually took place. Article 17(3)(c) allows a controller to refuse erasure where processing is necessary for reasons of public interest in the area of public health, and separate medical retention laws oblige your doctor to keep the record for a set number of years.

What we do instead is close the account and pseudonymise your identity, so the clinical record remains where the law requires but is no longer readily linked to you. If we refuse part of an erasure request we will tell you which part and why, in writing, within one month.

To exercise any right, write to [[privacy@z2ahealth.com]]. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. There is no charge unless a request is manifestly unfounded or excessive.

Every access to your health record by a member of staff or a doctor is logged, and you can see that log inside your account.

9. Security

If a breach occurs that is likely to result in a risk to your rights, we notify the supervisory authority within 72 hours and, where the risk is high, we notify you directly without undue delay.

10. Cookies

TypePurposeConsent needed?
SessionKeeps you signed inNo — strictly necessary
SecurityCSRF protection, abuse detectionNo — strictly necessary
PreferencesLanguage, currency, timezoneNo — you set them yourself
Analytics[[ONLY IF USED — AND IF USED, CONSENT IS REQUIRED BEFORE THE COOKIE IS SET]]Yes

We do not use advertising or cross-site tracking cookies. If we ever introduce analytics, you will be asked first and refusing will not degrade the service.

11. Children

Z2A Health accounts are for adults aged 18 or over. We do not knowingly create accounts for children. [[IF PAEDIATRIC CONSULTATIONS ARE OFFERED — AND THE PLATFORM LISTS PAEDIATRICIANS — THIS SECTION MUST EXPLAIN HOW A PARENT OR GUARDIAN HOLDS AN ACCOUNT ON A CHILD'S BEHALF, WHO CONSENTS, AND WHAT HAPPENS WHEN THE CHILD TURNS 18.]]

12. Changes to this policy

We will post any change here and update the version and date at the top. Where a change materially affects how we use your data, we will notify you by email before it takes effect, and where the change requires consent we will ask for it rather than assume it.

13. Contact and complaints

Questions or requests: [[privacy@z2ahealth.com]]

Data Protection Officer: [[NAME AND CONTACT]]

If you are unhappy with our response, you may complain to the data protection authority in your country of residence, work, or where you believe an infringement occurred. In Moldova, the authority is the National Centre for Personal Data Protection. A list of EU authorities is published by the European Data Protection Board. You may complain to a supervisory authority without contacting us first, though we would rather have the chance to put things right.