Privacy Policy

How ND Facemed PC collects, uses and protects your personal data under the GDPR.

Data Controller: ND Facemed PC — 2 Argolidos St., Athens 11523, Greece — tel. +30 210 69 29 999.
Data Protection Officer (DPO): Manos Mais — +30 698 428 1657 — privacy@facemed.gr.

1. Introduction

ND Facemed PC respects your privacy and processes personal data under GDPR and Greek Law 4624/2019.

2. Channels & data

  • Website: contact form, "Book Appointment", newsletter.
  • Messaging (WhatsApp/Messenger/Instagram): identifier, profile name, message content.
  • Technical/Analytics: cookies (see Cookies Policy).

3. Purposes & legal basis

  • Communication, appointments — consent or contract performance.
  • Messaging reminders — opt-in only, opt-out anytime.
  • Newsletter — with consent.

4. AI

Part of the responses on messaging channels is provided by an automated digital assistant. See AI Assistant Notice.

5. Health data

We do not request health data via chat.

6. Processors

  • Meta Platforms Ireland Ltd (messaging & advertising measurement)
  • Google Ireland Ltd (advertising measurement)
  • Infrastructure / database provider
  • Anthropic (Claude) — data not used for training
  • Payment providers

7. International transfers

Standard Contractual Clauses (SCCs) apply.

8. Retention

Messaging conversations are kept for 12 months.

9. Your rights

Access, rectification, erasure, restriction, objection, portability. Exercise: privacy@facemed.gr. See Data Deletion.

10. Opt-out

Send "STOP" on the relevant channel or email.

11. Changes

This policy may be updated.

12. Health data — GDPR Article 9

As a medical clinic, data relating to your physical or mental health (reason for visit, medical history, progress photographs) constitute a "special category of personal data" under Article 9 GDPR. Processing is based on your explicit consent (Art. 9(2)(a)) and/or on the provision of healthcare by a health professional bound by professional secrecy (Art. 9(2)(h) GDPR & Greek Law 3418/2005 "Code of Medical Ethics").

13. Processor — Topmedical

Appointment scheduling and customer communication are handled via Topmedical as a data processor, under a Data Processing Agreement (DPA) as required by Article 28 GDPR.

14. Retention periods

  • Contact form / appointment request: up to 24 months from last contact.
  • Patient medical record: at least 10 years from the last visit (Art. 14(4) L. 3418/2005).
  • Newsletter / marketing: until you withdraw consent.
  • Cookies: see Cookies Policy.
  • Accounting records: as required by Greek tax law (5+ years).

15. Right to lodge a complaint

You have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) — 1-3 Kifisias Av., 115 23 Athens, tel. +30 210 6475600, www.dpa.gr/en.

16. Advertising performance measurement

Where you have consented to marketing cookies, when you submit an appointment request or complete a purchase we transmit to Meta Platforms Ireland Ltd and Google Ireland Ltd a limited set of data used to measure the effectiveness of our advertising: the fact that a booking/purchase occurred, your email address and/or phone number in hashed (non-readable) form, the clinic of interest, a value range and technical advertising identifiers. We never transmit the service or treatment you are interested in, nor any health information. The legal basis is your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time from the cookie settings. These providers act as independent controllers for matching the data within their own systems. Standard Contractual Clauses (SCCs) apply to transfers outside the EEA.


Related policies: Privacy Policy · Terms of Use · Cookies Policy · Data Deletion · Refund Policy · Content Policy · AI Assistant