Privacy Policy

How we collect, use and protect your data.

Jovian Health Lab

PERSONAL DATA PROTECTION POLICY (GDPR)

This Data Protection Policy describes the way in which Jovian Health Lab, hereinafter referred to as the "Center", collects, processes, and protects the personal data of its patients, visitors, and partners, in accordance with the General Data Protection Regulation (EU 2016/679 – GDPR), Greek legislation, and the specific provisions governing healthcare services.

The Data Controller is the Medical Center located at 82 Vasilissis Sofias Avenue, with contact telephone number 2107489100 and website www.jovianhealth.gr. For any matter related to the protection of personal data, interested parties may contact us at info@jovianhealth.gr.

The Center collects the necessary data for the provision of healthcare services. During a visit or collaboration with the Center, identification data may be collected, such as full name, date of birth, address, contact details, and insurance information, as well as health data, including medical history, diagnoses, examinations, treatment records, and medication. Administrative and financial data for service invoicing may also be collected, as well as technical browsing data, such as cookies or usage statistics, if a website is used.

The Center does not collect data beyond what is necessary for the provision and organization of healthcare services.

Personal data is processed exclusively for the purposes of providing medical care, maintaining medical records, scheduling appointments, issuing referrals, medical certificates and test results, as well as communicating with patients regarding therapeutic instructions. In addition, the data is used for the fulfillment of tax and administrative obligations, as well as for cooperation with insurance providers when requested by the patient. No automated decision-making or profiling is carried out, except to the extent that this is strictly necessary for the provision of healthcare services.

The legal bases for data processing include the provision of healthcare services in accordance with Article 9 of the GDPR, compliance with legal obligations under Article 6, the performance of a contract under Article 6, and consent where required under Article 6.

Access to personal data is limited to authorized members of the Center's staff, such as doctors, therapists, and administrative personnel. Data may also be disclosed to collaborating diagnostic laboratories or insurance organizations where this is required for the provision of services or requested by the patient. In cases of legal obligation, access may be granted to the competent authorities.

All partners are bound by confidentiality clauses and data processing agreements. In the event that, in the future, the Center establishes or collaborates with new units operating under the Center's framework and status, access to personal data will be carried out exclusively through the Center's central database, under its direct supervision and control. These units will be required to strictly comply with the same high standards of security and personal data protection applied by the Center, in accordance with the GDPR and applicable legislation.

Personal data is retained for the period required by healthcare legislation, specifically for at least ten years, or for a longer period where necessary for the support of legal claims. Data collected on the basis of consent is retained until such consent is withdrawn. After the end of these periods, the data is securely deleted or anonymized.

Patients have a number of rights under the GDPR, including the right of access to their data, the right to rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent where consent constitutes the legal basis for processing.

The Center implements appropriate technical and organizational security measures to protect personal data, such as encryption, secure file storage, controlled access to health records, updated information system protection measures, confidentiality procedures, and data backup processes.

The Center does not transfer data to countries outside the European Union. If such a transfer is required in the future, it will be carried out in accordance with Articles 44–49 of the GDPR and only after the patient has been fully informed.

If any individual believes that their rights have been violated, they may contact the Center or the Hellenic Data Protection Authority through its website.

The Center reserves the right to update this policy whenever necessary. The latest version will be available at the Center's premises or on its website.

Who receives data

Beyond the clinic's own staff, the following third parties receive data so the service can run. For each one: what is sent, on what legal basis, and where it is located.

  • Mistral AI (France)

    European Union
    What is sent:
    The text of reports you upload, when they are read automatically, and the doctor's questions to the AI assistant. For report reading the text includes whatever is printed on the document — so your name and ΑΜΚΑ as well.
    Legal basis:
    Art. 9(2)(h) — provision of health care. EU-based processor under a data processing agreement.
  • Anthropic (Claude, ΗΠΑ / USA)

    United States
    What is sent:
    Only when explicitly selected for a task. The «ask about this client» chat sends anonymised data — age decade, sex and numeric values, with no name, ΑΜΚΑ, ΑΦΜ or contact details — and only if you have given explicit consent.
    Legal basis:
    Explicit consent (Art. 9(2)(a)) for the chat. Transfer outside the EU under standard contractual clauses.
  • Google Cloud (Φρανκφούρτη / Frankfurt)

    European Union
    What is sent:
    Hosts the server this system runs on and where the database is stored. Google does not read the data; it hosts it.
    Legal basis:
    Processor (Art. 28), inside the EU. The data does not leave Germany.
  • Google Calendar

    United States
    What is sent:
    NO patient data. When a doctor connects their schedule to their calendar, only the time, the service name, the doctor's name, the room and — for online visits — the meeting link are sent. Never a client name, ΑΜΚΑ, phone or notes.
    Legal basis:
    Legitimate interest (Art. 6(1)(f)) — organising the doctor's own schedule. Optional, per doctor.
  • ΑΑΔΕ — myDATA

    Greece
    What is sent:
    The fiscal details of each receipt: amount, VAT, date, and your ΑΦΜ when you ask for an invoice.
    Legal basis:
    Legal obligation (Art. 6(1)(c)) — Greek tax law.
  • Πάροχος email του ιατρείου / The clinic's email provider

    European Union
    What is sent:
    The emails the clinic sends you (appointment reminders, receipts, reports) and the ones you send the clinic.
    Legal basis:
    Processor (Art. 28) for communication about your care.
  • Πάροχος SMS / SMS gateway (easySMS)

    Greece
    What is sent:
    Your phone number and the message text, when the clinic sends you a reminder SMS.
    Legal basis:
    Processor (Art. 28). You can opt out of SMS at any time.

Integrations that do NOT receive data

These exist in the system but are switched off. They are listed here for completeness.

  • Fireflies.aiSWITCHED OFF. Disabled in August 2026 and stays off: it sent consultation audio to a third party without a signed processing agreement. It receives nothing today.
  • Apple (App Store)NOT ACTIVE. No app has been submitted to the App Store. Recorded in advance so the list is already correct on the day one is.
  • Google (Play Store)NOT ACTIVE. No app has been submitted to Google Play.

Your rights

You have the right of access, rectification, erasure, restriction, portability and objection, and to withdraw your consent. Contact the clinic using the details above. You may also lodge a complaint with the Hellenic Data Protection Authority.

Text version: v2.1