PROMOȚII

Descoperă promoțiile care îți fac bine!

Află mai multe
 

Privacy Notice Regarding the Processing of Personal Data for the iMed Application

In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”), through this Privacy Notice, we, MED LIFE S.A., with our registered office in Bucharest, 365 Calea Griviței, Sector 1, registered with the Bucharest Trade Registry under no. J1996003709402 and having unique registration code (CUI) 8422035 (hereinafter referred to as “MedLife”), acting as data controller, explain below when and why we process your personal data, how we use such data, the circumstances in which we may disclose them to others, and how we store them when you activate and use the iMed Application.

This Privacy Notice supplements MedLife’s general Privacy Policy and applies specifically to the iMed Application.

If you have any questions regarding how we process your personal data or wish to exercise any of the rights described below, you may contact our Data Protection Officer using any of the following methods:

What is the iMed Application

The iMed Application is an optional digital functionality available within the MedLife mobile application that allows users to view, in a centralized format, certain data available in their MedLife account and, if they choose, data obtained from connected external devices, as well as an indicative aggregated lifestyle/wellness score and certain descriptive statistical positioning relative to a reference population.

These scores and descriptive statistical positioning do not constitute a medical diagnosis, do not provide recommendations for medical investigations or treatments, and do not classify the user as having or not having a particular medical condition.

Categories of Personal Data Processed

MedLife may process the following categories of personal data, depending on the data available and the consents you have provided: MedLife account identification data; authentication and security data; laboratory test results; medical history data; medical history and anamnesis data; biometric and physiological data; lifestyle data; data relating to physical activity, sleep, or other parameters imported from external devices; genetic data or polygenic risk scores available in your medical record, if you choose to include them; data relating to your use of the Application; technical logs; and records of consents provided or withdrawn.

Sources of Personal Data

The data may be obtained from your MedLife account, from the history of services and results available in the MedLife mobile application, from information provided by you, from external devices connected via API (wearables), and from calculations generated by the Application based on such data.

When you import data from an external device, the provider of the device or associated platform may process your data as an independent data controller in accordance with its own privacy policy.

Categories of Personal Data Processed, Purposes and Legal Bases for Processing

 

Personal data processedPurpose of processingLegal basis
MedLife App Account Credentials, User Identifiers, SettingsActivating the App and linking it to your MedLife account

Art. 6 para. 1 letter (b) of the GDPR - Execution of pre-contractual steps/measures or performance of the contract

 

Health data, analytics, biometrics, history, lifestyle, PRS, wearable dataDisplay of aggregate scores, an indicative lifestyle/wellness indicator as well as descriptive statistical positioning scores in relation to a reference population

Art. 6 para. 1 lit. (a) of the GDPR – Your consent

 

Art. 9 para. 2 lit. (a) GDPR – Your explicit consent to the processing of health status data

Date de sănătate și date din wearables (de ex. informații privind activitatea fizică, pașii, somnul, ritmul cardiac, greutatea, caloriile, exercițiile, parametri fiziologici sau alte date disponibile în wearables) agregate temporalDisplay data evolution over time

Art. 6 para. 1 lit. (a) of the GDPR – Your consent

 

Art. 9 para. 2 lit. (a) GDPR – Your explicit consent to the processing of health status data

Data from wearables (e.g., information about physical activity, steps, sleep, heart rate, weight, calories, exercise, physiological parameters, or other data available in the wearable), API identifiers, permissionsImporting data from external devices

Art. 6 para. 1 lit. (a) of the GDPR – Your consent

 

Art. 9 para. 2 lit. (a) GDPR – Your explicit consent to the processing of health status data

Genetic data, polygenic risk scoresInclusion of genetic/PRS data in the form of a score for descriptive statistical positioning in relation to a reference population

Art. 6 para. 1 lit. (a) of the GDPR – Your consent

 

Art. 9 para. 2 lit. (a) GDPR – Your explicit consent to the processing of health status data

Logs, technical identifiers, security eventsApp Security and Preventing Unauthorized Access

Art. 6 para. 1 letter (f) of the GDPR – The legitimate interest to protect the application or Art. 6 para. 1 lit. (c) of the GDPR – Processing is necessary for the fulfilment of a legal obligation

 

Consent history, withdrawals, document versionsEvidence of consents and demonstration of compliance

Art. 6 para. 1 letter (f) of the GDPR – The legitimate interest to protect the application or Art. 6 para. 1 lit. (c) of the GDPR – Processing is necessary for the fulfilment of a legal obligation

 

Identification data, data covered by the applicationResolution of GDPR rights requestsArt. 6 para. 1 lit. (c) of the GDPR – Processing is necessary for the fulfilment of a legal obligation
Aggregated, pseudonymised data or, if necessary, personal dataAlgorithm improvement, if enabled separately

Art. 6 para. 1 lit. (a) of the GDPR – Your consent

 

Art. 9 para. 2 lit. (a) GDPR – Your explicit consent to the processing of health status data

Aggregated, anonymized/pseudonymized data or, if necessary, personal dataAnonymization or pseudonymization of data and their inclusion in statistics and scientific research studies in the medical field

Art. 6 para. 1 lit. (a) GDPR – Your consent

 

Art. 9 para. 2 lit. (a) GDPR – Your explicit consent to the processing of health data

 

Profiling and Automated Decision-Making

The Application involves profiling within the meaning of the GDPR, as it processes personal data for the purpose of displaying an indicative aggregated lifestyle/wellness score and descriptive statistical positioning relative to a reference population. The scores do not produce legal effects concerning you or similarly significantly affect you, as they do not automatically determine access to services, pricing, appointments, eligibility, diagnosis, or treatment.

Where profiling involves genetic, biometric, or health data, MedLife applies the additional safeguards provided for under Article 3 of Law No. 190/2018, with such processing being carried out exclusively on the basis of your explicit consent and subject to specific technical and organizational measures designed to protect your rights and freedoms.

You will not be subject, solely as a result of using the dashboard, to a decision based exclusively on automated processing that produces legal effects concerning you or similarly significantly affects you.

 

Recipients of Personal Data

Personal data may be accessed by authorized MedLife personnel only to the extent necessary for the administration, security, and functional support of the Application. Personal data may also be processed by technical service providers, hosting providers, developers, security service providers, support providers, and other partners acting, as applicable, as data processors or independent data controllers. Where such partners act as data processors, the processing is carried out pursuant to data processing agreements concluded in accordance with Article 28 of the GDPR, which require appropriate safeguards for the confidentiality and security of personal data.

Data from external devices are imported based on the permissions you have granted. MedLife does not ordinarily transmit the score back to the device provider unless such transmission is expressly described and authorized.

 

International Data Transfers

As a general rule, we will not transfer your personal data outside the European Economic Area (EEA). In exceptional circumstances, and only where necessary, any transfer of your personal data outside the EEA will be carried out only with appropriate safeguards in place in accordance with Articles 44–49 of the GDPR (for example, Standard Contractual Clauses) and with appropriate notice provided to you.

Please note that, if you choose to connect an external device (wearable), the provider of that device or the associated platform may be established outside the EEA (for example, in the United States of America) and may process your personal data as an independent data controller, in accordance with its own privacy policy and international data transfer mechanisms, over which MedLife has no control.

 

How Long We Retain Your Personal Data

The data used for the Application are retained for as long as the functionality remains active. Following deactivation of the Application or withdrawal of consent, data specific to the Application will be retained for a maximum period of 30 days, as necessary to complete the technical deactivation process and cease the relevant processing activities.

By way of exception, the following will be retained: (i) records of consents given and withdrawn, for the period during which MedLife may be held liable and, in any event, for the general limitation period of three years; (ii) technical and security logs, for a maximum period of 12 months; and (iii) data required to comply with specific legal obligations, for the period prescribed by applicable law. Health data and genetic data will be deleted or anonymized upon expiry of the applicable retention periods.

Following deactivation of the Application or withdrawal of consent, MedLife will cease calculating scores and statistical positioning and will delete or anonymize data specific to the Application, except for data that must be retained for other lawful purposes.

 

Your Rights

Unless otherwise provided by law, you have the following rights in relation to your personal data:

(i) the right of access to your personal data – the right to obtain confirmation from us as to whether we process your personal data and, where this is the case, the right to access such data and obtain information about the processing;

(ii) the right to request rectification of your personal data – the right to request, without undue delay, the correction of inaccurate personal data or the completion of incomplete personal data;

(iii) the right to request erasure of your personal data where you consider that the personal data are no longer necessary for the purposes for which they were collected or processed and there is no other legal basis for the processing, where they have been unlawfully processed by us, or where the data must be erased in order to comply with a legal obligation;

(iv) the right to request restriction of processing where: (a) you contest the accuracy of the data; (b) the processing is unlawful and you oppose the erasure of the data and request restriction of their processing instead; (c) the data are no longer necessary for the processing carried out by the Company, but you require them for the establishment, exercise or defence of legal claims; or (d) you object to processing carried out by us on the basis of our legitimate interests;

(v) the right to object to the processing of personal data based on the Company’s legitimate interests – unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or that the processing is necessary for the establishment, exercise or defence of legal claims;

(vi) the right to data portability – the right to receive the personal data you have provided to the Company in a structured, commonly used and machine-readable format, as well as the right to transmit those data to another data controller;

(vii) the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, except where we have duly obtained your consent for such processing;

(viii) the right to withdraw your consent at any time in relation to processing activities based on consent, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal;

(ix) the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), at 28–30 General Gheorghe Magheru Blvd., Sector 1, postal code 010336, Bucharest, telephone: 0318 059 211, via www.dataprotection.ro, regarding the processing of your personal data.

 

Data Security

MedLife implements appropriate technical and organizational measures, including access controls, encryption, logging, segmentation, monitoring, security testing, and internal incident management procedures. The level of these measures is tailored to the high level of risk associated with the processing of health and genetic data. 

The processing of your health data is carried out in compliance with medical professional secrecy and patient data confidentiality requirements, in accordance with Law No. 46/2003 on Patients’ Rights and Law No. 95/2006 on Healthcare Reform.

Given the large-scale processing of special categories of personal data, MedLife has carried out a Data Protection Impact Assessment (DPIA) in accordance with Article 35 of the GDPR.

©2026 Acest site este proprietatea MedLife S.A. Toate drepturile rezervate.