General Provisions and Identification of the Controller
Art. 1. (1) This Privacy Policy (the “Policy”) describes how DocNow Medical Services EOOD, UIC 208622091, with registered office and management address: Sofia 1404, Triaditsa district, 109 Bulgaria Blvd., floor 2, office 2.5, email: [email protected], tel.: +359 889 999 955 (hereinafter the “Company”, “we”, “us” or “our”), collects, uses, stores, shares and protects natural persons' personal data in connection with the OneCare platform (the “Platform”), accessible at www.onecare.bg and through the OneCare mobile application, regardless of its version and the operating system of the device, including through all its sections, pages, interfaces, electronic forms and related functionalities.
(2) The Company is a controller of Personal Data within the meaning of Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”) for the Processing operations for which it independently determines the purposes and means of the Processing.
(3) For certain operations in which the Company processes Personal Data on behalf of and on the instructions of the relevant Service Provider (including, but not limited to, a medical establishment, veterinary practice and others), the Company acts as a Personal Data Processor within the meaning of Article 28 GDPR. For certain operations in which the Company and the Service Provider jointly determine the purposes and essential means of Processing, they act as joint controllers within the meaning of Article 26 GDPR. The allocation of roles by type of operation is described in Section XIII and governed by a separate agreement between the Company and the Service Provider.
(4) For any questions concerning the Processing of Personal Data, you may contact us by email at [email protected] or [email protected].
(5) When Processing Personal Data, the Company complies with the following principles in accordance with Article 5 GDPR:
1. lawfulness, fairness and transparency - data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject;
2. purpose limitation - data shall be collected for specified, explicit and legitimate purposes and shall not be processed in a manner incompatible with those purposes;
3. data minimisation - only data that are adequate, relevant and limited to what is necessary in relation to the purposes of the Processing shall be processed;
4. accuracy - data shall be kept accurate and, where necessary, up to date;
5. storage limitation - data shall be kept in a form which permits identification of the data subject for no longer than is necessary for the purposes of the Processing;
6. integrity and confidentiality - data shall be processed in a manner that ensures an appropriate level of security;
7. accountability - the Company is responsible for and is able to demonstrate compliance with these principles.
Art. 2. (1) This Policy applies to the following categories of persons:
1. Users - natural persons who register on, browse or use the Platform;
2. Service Recipients: natural persons for whom the User orders a service, including children and other third parties. For veterinary services, the Service Recipient is the animal, and data concerning it are processed as Personal Data of the User or the animal's owner insofar as they allow that person to be identified;
3. Service Providers and natural persons associated with them: Service Providers who are natural persons, and representatives, employees, associates and other natural persons through whom the Service Provider supplies services or uses the Platform, including persons whose data are displayed in the Service Provider Account;
4. Visitors - persons who visit the Platform without registering;
5. Contact Persons: persons who contact the Company through contact forms, email, telephone or another communication channel;
6. Voucher Holders: persons to whom a voucher has been provided, including where they are not the person who paid for it;
7. Complainants and Notice Submitters: persons who submit a complaint, notice, objection or request under the General Terms and Conditions, including a notice of illegal content, regardless of whether they are registered in the Platform.
(2) This Policy applies together with the General Terms and Conditions for Use of the OneCare Platform. In the event of any conflict regarding personal data protection matters, this Policy shall prevail.
(3) This Policy is available at all times in the Platform, both through the website and through the mobile application, and is provided to Users and Service Providers upon registration. The Policy is published at a permanent, publicly accessible internet address that requires no registration or account login, is not geographically restricted and is not a file requiring download. The same address is provided to the relevant application store.
Definitions
Art. 3. (1) For the purposes of this Policy:
1. “Personal Data” means any information relating to an identified natural person or a natural person who can be identified directly or indirectly, in particular by an identifier such as a name, identification number, location data, online identifier or one or more factors specific to that person's physical, physiological, genetic, psychological, mental, economic, cultural or social identity.
2. “Processing” means any operation or set of operations performed on Personal Data or sets of Personal Data, by automated or other means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
3. “Special Categories of Personal Data” means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, health data or data concerning a natural person's sex life or sexual orientation.
4. “Health Data” means Personal Data relating to a natural person's physical or mental health, including the provision of health services, which reveal information about their health status.
5. “Controller” means a natural or legal person who, alone or jointly with others, determines the purposes and means of Processing Personal Data, including the Company and the Service Provider, each in respect of the operations for which it determines the purposes and means.
6. “Personal Data Processor” means the Company or another person who processes Personal Data on behalf of a controller.
7. “Mobile Application” means the OneCare mobile application through which the Platform is accessed, regardless of its version, the application store from which it was obtained and the operating system of the device. The Mobile Application is part of the Platform, and every reference to the Platform also includes it unless expressly stated otherwise.
8. “Push Notification” means a message delivered to the relevant person's device through the notification infrastructure of the operating system or a notification service provider and displayed outside the Platform interface.
9. “In-Platform Message” means a message generated by the Company and displayed in the Platform interface, including a banner, pop-up window, card or Account message, while the person concerned uses the Platform.
(2) All other terms, apart from those in paragraph 1, used but not expressly defined in this Policy have the meanings assigned to them in the General Terms and Conditions for Use of the OneCare Platform or applicable legislation.
Categories of Personal Data We Collect
Art. 4. (1) When registering in the Platform, the User provides:
1. first and last name;
2. email address;
3. telephone number, including country code;
4. a password, which is stored only in irreversibly encrypted form and is not accessible to the Company.
(2) Upon registration, the User confirms acceptance of the General Terms and Conditions and acknowledgement of this Policy, and declares that they are at least 18. The Company records the time of confirmation, the accepted version of the General Terms and Conditions and the Policy, and the IP address from which confirmation was made. The Company does not require an identity document to verify age upon registration.
(3) Upon registration, the User may choose to tick a separate box consenting to receive marketing communications. The box is not preselected, and ticking it is not a condition of registration. The Company records the time consent is given, changed or withdrawn, its scope and the IP address.
(4) Registration and subsequent login may also be performed through the User's account with an external authentication service provider, including Google, Apple and Facebook. In that case, the Company receives from the provider only the data needed to create the Account: the account identifier with the provider, names and email address, or, where the provider offers email hiding, a forwarding address generated by it. The Company has no access to the User's password with the provider and receives no other data from that account. The scope of data supplied is determined by the provider and the User's choices in its interface, and the provider's processing is governed by its terms and privacy policy.
(5) After the registration form is submitted, the Company sends a message with a one-time confirmation link to the specified email address. For this purpose, it processes the email address, User's name, generated confirmation code, date and time of sending, opening and confirmation, and delivery status.
(6) After confirming the email address, the User may add an address where they wish to receive services. For each address, the locality and address, including neighbourhood, street, number, building, entrance, floor and apartment, postal code and any additional information the User chooses to supply for locating and accessing the premises are processed. The User may store more than one address and change or delete them at any time through their Account.
(7) Services offered through the Platform are performed at an address specified by the User, and Online Consultations remotely, through the technical method specified in the Platform. When a service is ordered and performed, the Company processes, insofar as relevant to that service:
1. the selected performance address and access details;
2. the selected service category, particular service, date, time or time slot;
3. payment and payment status data, including the transaction reference number, the last four digits and type of the card, where applicable, and the code of any voucher or promotional code used;
4. notes, comments and additional information supplied by the User;
5. a personal identification number (ЕГН) or foreigner's personal number (ЛНЧ), or, for foreigners without an ЕГН or ЛНЧ, date of birth and identity document details, only for services where legislation or an applicable professional rule requires identification of the Service Recipient, including medical, laboratory and other health services;
6. Service Recipient health data where necessary for ordering or performing the service or supplied by the User, Service Recipient or Service Provider, including complaints, symptoms, diagnoses, prescriptions, results and documents;
7. animal data for veterinary services: species, breed, sex, age, weight, complaints and other relevant information;
8. ratings, reviews and feedback, and data enabling the Company to establish that a rating or review originates from a person who actually ordered and received the relevant service;
9. the content of communications concerning the Order Request where conducted through the Platform;
10. performance progress data: Order Request status, timestamps, rescheduling, cancellation, No-Show and circumstances preventing performance.
(8) Where the User requests an invoice, the Company also processes the data necessary to issue it. For a natural person not acting as a taxable person, these are the person's names and address and, at their request, a personal identification number if they wish it to appear on the invoice. Where the person acts as a taxable person or wants the invoice issued to a legal entity or another merchant, the name, registered office and address, identification number and VAT identification number are processed where applicable. The data under this paragraph are processed to issue the invoice and related accounting documents and to fulfil the Company's obligations under the Accountancy Act, the Value Added Tax Act and applicable tax legislation.
(9) Where the User orders a service for a Service Recipient other than themselves, they provide that person's data to the extent specified in paragraphs 1 and 7, insofar as necessary for the relevant service, declaring and warranting that they are entitled to provide them and have met the applicable requirements under Article 9 of the General Terms and Conditions.
(10) Full card details, including card number, expiry date and security code, are entered by the User directly in the secure environment of the relevant payment service provider and are not stored, recorded or processed by the Company. The Company receives from the payment service provider only the transaction result, a reference number and, where applicable, the last four digits and type of the card, insofar as necessary to identify the payment, issue documents and process disputes, refunds and reversals. Full card details are processed by the payment service provider under its terms and privacy policy. Where payment is made through an application store's payment mechanism, payment data are processed by the store provider under its terms and privacy policy, and the Company receives only transaction result and identification data. Where the User pays through an electronic wallet of the mobile operating system provider (Apple Pay, Google Pay or similar), card details are not entered in the Platform or transmitted to the Company; payment is made through a unique device identifier generated by the relevant wallet provider. The wallet provider processes payment data under its terms and privacy policy and supplies the payment service provider and the Company only with the data necessary to execute and identify the transaction.
(11) The categories and volume of data collected under this Article may be changed, expanded or reduced according to the type of service, legal requirements, Platform functionalities and the needs of the relevant service category. When collection of a new data category is introduced, the User is informed before or at the time of collection.
(12) Data under this Article are processed in the Company's environment, maintained through its infrastructure providers under Article 11, paragraph 1, item 2, and in the environments of the other technical providers under that provision, depending on the specific purpose of Processing and the Platform's technical requirements.
Art. 5. (1) When creating a Service Provider profile on the Platform, the Company collects:
1. name (business name), UIC/BULSTAT, legal form;
2. registered seat and management address;
3. details of the representative and other natural persons designated by the Service Provider for contact or signing: names, personal identification number (ЕГН), position;
4. email address, telephone, correspondence address;
5. data on registrations, permits, licences, professional rights, qualifications and insurance;
6. bank and/or payment data for the transfer of remuneration;
7. schedule, availability and scope of services offered, including the areas in which the Service Provider accepts Order Requests.
(2) For the Service Provider's specialists, employees and associates whose profiles or data are displayed in the Platform, the Company may process:
1. full name, professional title, specialty, position;
2. unique identification number (UIN) or another professional identifier;
3. professional photograph, short biography, education and qualification data;
4. email address, telephone, correspondence address;
5. schedule, locations and availability.
(3) Data under paragraph 2 are processed on the basis of the contractual relationship between the Company and the Service Provider.
(4) When the Service Provider uses the Platform and performs Order Requests, the Company also processes:
1. data on accepted Order Requests, cancellations, rescheduling, performance and reporting;
2. location data where such functionality is used, including to record arrival and attempted performance of the service;
3. ratings, reviews and feedback concerning the Service Provider and the persons through whom it supplies services;
4. the content of communications conducted through the Platform;
5. data on measures imposed under the General Terms and Conditions and their grounds.
(5) Data under paragraphs 2 and 4 are also processed in respect of the natural persons through whom the Service Provider supplies services, including where their profiles are not displayed in the Platform.
Art. 6. (1) When visiting and using the Platform, the following data are collected automatically:
1. IP address;
2. browser type and version, operating system;
3. date, time and duration of visits;
4. pages visited and actions performed on the Platform;
5. traffic source (referrer URL);
6. unique device identifiers (device IDs), where applicable;
7. data from cookies and similar technologies in accordance with Section VIII of this Policy.
(2) When the Mobile Application is used, the following are collected in addition to the data under paragraph 1:
1. device model and type, operating system version, Mobile Application version, and device language and time zone;
2. a unique installation identifier and an identifier (token) for delivery of Push Notifications;
3. diagnostic data and data on Mobile Application errors, crashes and performance;
4. data on interaction with Push Notifications and In-Platform Messages, including delivery, display, opening and dismissal;
5. the device advertising identifier, where used and after the necessary permission has been given through the operating system. The advertising identifier is not used for advertising based on Health Data or other Special Categories of Personal Data. The Company does not track Users in applications and websites owned by other companies or link data collected through the Mobile Application with data from such sources for advertising or advertising measurement unless the User has given express permission through the operating system's cross-application tracking mechanism, which may be withdrawn at any time through device settings;
6. data relating to obtaining and updating the Mobile Application through the relevant application store, insofar as supplied to the Company by the store provider.
(3) Certain Mobile Application functionalities require permission granted through the device operating system. The Company may request permission to send notifications and access location and, upon introduction of the corresponding functionalities, to access the calendar, camera, microphone, photos and files. Permission is requested when the functionality is first used and may be withdrawn at any time through device settings, in which case the functionality may cease to work or work only to a limited extent. Withdrawal has no retroactive effect on data already collected.
(4) Where location access permission has been granted, location data are processed to complete and verify the performance address, select a Service Provider by geographical proximity, record arrival and attempted performance of the service, and for other functionalities where location is objectively necessary and about which the person concerned is informed. The Company does not continuously track the device outside these cases.
(5) Push Notifications and other notifications delivered to the device do not contain Health Data, other special categories of Personal Data or other sensitive or confidential information. Notification content is minimised and, where necessary, neutral wording is used that does not disclose such information.
Art. 7. (1) When you contact the Company by email, contact form, telephone, instant messaging application or another communication channel, the Company processes the data you provide: names, contact details, message content and any other information you choose to provide, for the purposes of handling your enquiry and maintaining correspondence.
(2) Communication may take place by email, text message, telephone call, Push Notification, In-Platform Message, instant messaging applications including Viber, WhatsApp, Telegram and Signal, and through an embedded Platform chat when that functionality is introduced. Messages sent through an instant messaging application are delivered through that application's infrastructure and, where the Company uses an intermediary to send them, also through that intermediary's infrastructure.
(3) The Company may conduct telephone calls with Users, Service Recipients and Service Providers, including through a service centre, calls made through the Platform and forwarding or masking of telephone numbers so that the parties can contact each other without disclosing their numbers to each other. Such calls involve processing data on telephone numbers, date, time, duration and call outcome.
(4) The Company may record telephone calls to prove the content of communications, consider complaints, monitor quality, train staff and defend legal claims. Recording takes place after advance notice at the beginning of the call. A person who does not wish the call to be recorded may end the call and contact the Company through another channel listed in the Platform.
Art. 8. (1) Where you have given separate, freely given and explicit consent by signing a consent declaration, the Company and/or the Service Provider may record and use your photographs, video and audiovisual materials for marketing, representative and informational purposes described in detail in the relevant declaration.
(2) The taking and public use of photographs and video is not a condition for the provision of the service and does not affect your right to receive the service without such recording.
(3) Where the Platform offers an online consultation or other real-time communication through audio and/or video, the Company processes the data necessary to establish the connection, including session identifier, date, time and duration, technical connection and quality data, and the content of the audio and video stream as it is transmitted. The recording is not stored in third-party consumer cloud services and is not used for advertising or marketing purposes.
(4) The Online Consultation is not recorded unless legislation or an applicable professional rule requires such a recording to be made or retained. Where a recording is made, the Company is the Controller of the recording and ensures its storage and the provision of access to it, while the Service Provider uses the Platform as the technical environment for the consultation. Participants are notified before recording begins.
(5) The recording under paragraph 4 is processed subject to professional secrecy, retained for the period prescribed by applicable legislation and provided only to persons and authorities entitled to access it.
(6) The information the Company provides to application store providers about the data collected, purposes of Processing and sharing with third parties, including in the data safety section and the application's privacy declaration, corresponds to this Policy. If a discrepancy is identified, this Policy applies and the Company updates the relevant declaration without undue delay.
Purposes and Legal Grounds for Processing
Art. 9. (1) The Company processes Personal Data for the following purposes and on the following legal grounds under the GDPR:
1. Registration and maintenance of a user account - legal ground: Article 6(1)(b) GDPR (performance of a contract);
2. Requesting, organising, administering and performing a specific service - legal ground: Article 6(1)(b) GDPR (performance of a contract);
3. Processing of Personal Data in connection with medical and healthcare services, including data concerning health - legal ground: Article 9(2)(h) GDPR (provision of health care) in conjunction with Article 6(1)(b) GDPR;
4. Processing of payments, issuance of fiscal, payment and accounting documents legal ground: Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(c) GDPR (legal obligation);
5. Provision of mandatory pre-contractual information under the Bulgarian Consumer Protection Act - legal ground: Article 6(1)(c) GDPR (legal obligation);
6. Fulfilment of accounting, tax, social security and other regulatory obligations legal ground: Article 6(1)(c) GDPR (legal obligation);
7. Sending marketing communications electronically, including by email, text message, Viber or another instant messaging channel and Push Notifications: legal basis: Article 6, paragraph 1, point (a) GDPR (consent), and, for direct marketing to existing customers concerning the Company's own similar services, Article 6, paragraph 1, point (f) GDPR (legitimate interest) in the cases provided by law, with the right to object at any time. Marketing communications may also include partner offers sent by the Company in its own name without providing Personal Data to partners for their independent marketing purposes;
8. Displaying In-Platform Messages with promotional content, including pop-up and embedded messages, while the person uses the Platform, including where tailored to their Order Request history and behaviour: legal basis: Article 6, paragraph 1, point (f) GDPR (legitimate interest in direct marketing in connection with the Platform and the services and offers available through it), with the right to object at any time under Article 21 GDPR. These messages are not based on Health Data or other Special Categories of Personal Data, subject to Article 10, paragraph 5.
9. Analytics, statistics and improvement of the Platform and user experience - legal ground: Article 6(1)(f) GDPR (the Company’s legitimate interest in improving its services);
10. Platform security, prevention of abuse, unauthorised access and fraud - legal ground: Article 6(1)(f) GDPR (legitimate interest);
11. Establishment, exercise or defence of legal claims - legal ground: Article 6(1)(f) GDPR (legitimate interest) and/or Article 9(2)(f) GDPR for special categories;
12. Conducting an online consultation through audio and/or video and, where legislation or a professional rule requires it, making and retaining a recording of the consultation: legal basis: Article 6, paragraph 1, point (b) GDPR for establishing the connection, and for Health Data and the recording, Article 9, paragraph 2, point (h) in conjunction with Article 9, paragraph 3 GDPR or Article 9, paragraph 2, point (c) GDPR (protection of vital interests), where applicable
13. Recording and public use of photographs and video for marketing, representative and informational purposes - legal ground: Article 6(1)(a) GDPR (consent), and where the images reveal health information - Article 9(2)(a) GDPR (explicit consent);
14. Creation, maintenance and display of a Service Provider profile and of its professionals on the Platform - legal ground: Article 6(1)(b) GDPR (performance of a contract between the Company and the Service Provider), and for the public display of photographs and extended information - Article 6(1)(a) GDPR (consent of the professional);
15. Processing of complaints, reports, enquiries and communication - legal ground: Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(f) GDPR (legitimate interest);
16. Sending transactional, service and information messages, including reminders of upcoming services, confirmations, notifications of changes, rescheduling, cancellation and Order Request status, to both Users and Service Providers by email, text message, telephone call, Viber, WhatsApp, Telegram, Signal or another instant messaging channel, Push Notifications and In-Platform Messages: legal basis: Article 6, paragraph 1, point (b) GDPR (performance of a contract) and, in respect of Service Providers who are not natural persons party to the contract, Article 6, paragraph 1, point (f) GDPR (legitimate interest in performing Order Requests).
17. Selecting a Service Provider for a particular Order Request, including through automated matching by availability, service category, location and other objective criteria: legal basis: Article 6, paragraph 1, point (b) GDPR (performance of a contract);
18. Publishing and maintaining ratings and reviews, including verifying that they originate from a person who actually ordered and received the service: legal basis: Article 6, paragraph 1, point (f) GDPR (legitimate interest in reliable ratings and protecting Users and Service Providers);
19. Issuing, maintaining, using and replacing vouchers and promotional codes: legal basis: Article 6, paragraph 1, point (b) GDPR (performance of a contract);
20. Fulfilling the Company's obligations under Regulation (EU) 2022/2065 (Digital Services Act), including receiving and considering notices of illegal content, taking measures and internally handling complaints, and using technical tools to detect and label potentially illegal or impermissible content: legal basis: Article 6, paragraph 1, point (c) GDPR (legal obligation), and outside the scope of the legal obligation, Article 6, paragraph 1, point (f) GDPR (legitimate interest in the Platform's security and proper functioning);
21. Recording acceptance of the General Terms and Conditions and this Policy and their respective versions, and the giving, amendment and withdrawal of consent, for accountability under Article 5, paragraph 2 and Article 7, paragraph 1 GDPR: legal basis: Article 6, paragraph 1, point (c) GDPR (legal obligation) and Article 6, paragraph 1, point (f) GDPR (legitimate interest in demonstrating compliance);
22. Verifying performance and the circumstances of a No-Show, including through time records and, where applicable, location data: legal basis: Article 6, paragraph 1, point (b) GDPR (performance of a contract) and Article 6, paragraph 1, point (f) GDPR (legitimate interest in resolving disputes);
23. Issuing invoices and related documents at the User's request: legal basis: Article 6, paragraph 1, point (c) GDPR (legal obligation).
(2) Where the Processing is based on your consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of the Processing carried out before the withdrawal. Withdrawing consent is as easy as giving it.
(3) Where the Processing is based on the Company’s legitimate interest, you have the right to object to the Processing pursuant to Article 21 GDPR, in the manner set out in Section X of this Policy.
Processing Special Categories of Personal Data
Art. 10. (1) In the case of certain types of services offered through the Platform (medical, veterinary, child care-related and others), Special Categories of Personal Data, in particular data concerning health, may be Processed.
(2) The Processing of Special Categories of Personal Data is carried out on one or more of the following legal bases:
1. Article 9, paragraph 2, point (h) in conjunction with Article 9, paragraph 3 GDPR, where Processing is necessary for preventive or occupational medicine, medical diagnosis, the provision of healthcare or treatment, or management of health services on the basis of Union or Bulgarian law, and the data are processed by or under the responsibility of a professional subject to professional secrecy or another person also subject to that duty;
2. Article 9(2)(a) GDPR - explicit consent of the data subject, where the other legal bases are not applicable;
3. Article 9, paragraph 2, point (f) GDPR, for establishing, exercising or defending legal claims;
4. Article 9, paragraph 2, point (c) GDPR, where Processing is necessary to protect the vital interests of the data subject or another natural person where the data subject is unable to give consent.
(3) In the case of non-medical services (cleaning, gardening, household services and other similar services), Special Categories of Personal Data are generally not processed. If Processing of such data is required for a particular service, the User shall be expressly informed and consent shall be requested where necessary.
(4) The Company processes data concerning health under conditions of professional secrecy and in compliance with the technical and organisational protection measures provided for in this Policy and in the applicable legislation.
(5) The Company does not use Health Data or other Special Categories of Personal Data for direct marketing, advertising, profiling for marketing or advertising purposes, usage-based data mining or In-Platform Messages with promotional content, and does not supply them to third parties for such purposes. The prohibition in the preceding sentence is unconditional and cannot be overridden by consent.
Recipients and Sharing of Personal Data
Art. 11. (1) The Company may share your Personal Data with the following categories of recipients, insofar as this is necessary to achieve the purposes described in this Policy:
1. Service Providers - medical establishments, medical professionals, veterinary practices, cleaning companies, child care specialists, gardeners and other persons providing services through the Platform, insofar as sharing is necessary for requesting, organising and performing the specific service;
2. Technical Providers (Personal Data Processors): persons supplying the Company with technical, infrastructure, hosting, communication, application, payment, support and other services necessary for the Platform's operation. These providers process Personal Data only on the Company's documented instructions, to the extent necessary for the relevant service and subject to Article 28 GDPR. Such provider categories include:
а) an infrastructure, hosting and data storage provider whose environment hosts the Platform, databases, uploaded files and backups (including Railway Corporation, Delaware, USA, with processing in a European Union region, Amsterdam; the underlying infrastructure is supplied through cloud service providers used by Railway;
б) a file and backup storage provider (currently Cloudflare, Inc., USA, through the Cloudflare R2 object storage service, with storage restricted to the European Union region);
в) an email delivery service provider (currently SendGrid);
г) a provider of text messaging and messaging through Viber, WhatsApp, Telegram, Signal or another instant messaging channel, including LINK Mobility for text messages and Viber;
д) Push Notification delivery service providers: the messaging service provider for the relevant mobile operating system, namely Google Ireland Limited, Ireland, or Google LLC, USA, for Android devices, and Apple Distribution International Ltd., Ireland, or Apple Inc., USA, for iOS devices; the notification delivery identifier and notification content are transmitted to these providers;
е) a Mobile Application error detection and performance monitoring service provider (currently Sentry);
ж) an address autocomplete, verification and geocoding service provider (currently Google Ireland Limited, Ireland, through Google Maps Platform services, with possible data transfers to Google LLC, USA);
з) providers of software components embedded in the Mobile Application for error detection, crash reporting, performance measurement, usage analytics, remote configuration and campaign effectiveness measurement (currently Sentry for error detection and performance monitoring and Google Ireland Limited, Ireland, or Google LLC, USA, through Firebase components); data transmitted through these components are processed subject to Article 10, paragraph 5 and Article 11, paragraph 1, item 3;
и) other technical providers in the listed categories supporting the Platform's operation. Specific providers are given as examples. Adding, replacing or removing a provider within a category and purpose described in this item does not constitute an amendment to this Policy. The current list of Personal Data Processors is supplied on request in accordance with Article 1, paragraph 4.
3. Analytics and Advertising Providers: providers of services for usage analysis, advertising campaign effectiveness measurement and improvement of the Platform and Mobile Application, including through software components embedded in the Mobile Application, subject to Section VIII of this Policy and after obtaining the necessary consent where required. These providers are not supplied with Health Data, other Special Categories of Personal Data or data concerning a particular ordered medical, veterinary medical or other health service that allow conclusions to be drawn about a particular person's health;
4. Professional advisers - lawyers, accountants, auditors, tax advisers and other persons providing the Company with legal, accounting, tax or audit services;
5. Marketing partners - marketing agencies, designers, content specialists and other persons supporting the Company in carrying out advertising and marketing activities, insofar as this is necessary and subject to the relevant legal ground;
6. Payment Intermediaries and Banks: banks, payment service providers, payment processors (including, but not limited to, PayNovus, Viva Wallet, ICashPOS or another provider specified in the Platform, electronic wallet providers Apple Distribution International Ltd. and Google Ireland Limited where payment is made through Apple Pay or Google Pay, and the provider of the relevant application store's payment mechanism where it is used) and other persons involved in processing payments, to whom transaction data and, where applicable, bank card details are transmitted directly by the User through the payment processor's secure environment;
7. Public Authorities and Institutions: Commission for Personal Data Protection (КЗЛД), Commission for Consumer Protection (КЗП), National Revenue Agency (НАП), Communications Regulation Commission (КРС) as Digital Services Coordinator, courts, prosecution authorities, police and other competent authorities where disclosure is required by law or an act of a competent authority.
(2) The Company does not sell, rent out or provide your Personal Data to third parties for remuneration for the independent marketing purposes of those parties.
(3) Where a Platform functionality involves logging in or sharing through the User's account with an external authentication service provider (including Google, Apple and Facebook), data exchange with that provider takes place at the User's choice and is governed by that provider's terms and privacy policy; the provider acts as an independent controller for processing in its own environment.
(4) The Company may disclose Personal Data to an acquirer or successor in a restructuring, transfer of an undertaking or a separate part of it, asset sale or similar transaction, subject to applicable legislation and appropriate data protection safeguards.
(5) The Company grants a third party access to Personal Data only where that person ensures a level of protection equivalent to that provided by this Policy and applicable legislation. This requirement applies to all recipients under paragraph 1, including technical providers, analytics and advertising providers, software components embedded in the Mobile Application and persons affiliated with the Company who would have access to Personal Data. Compliance is secured by a processing agreement under Article 28 GDPR, a joint controller agreement under Article 26 GDPR or another binding contractual arrangement; in the event of non-compliance, the Company stops providing data to that person.
(6) The Company does not transmit through analytics software components embedded in the Mobile Application data that alone or in combination allow conclusions to be drawn about a particular person's health, including through screen names, event names and parameters, and service and service category identifiers. Neutral labels are used for analytics purposes that do not reveal the type of ordered service where it is health-related.
Transfers of Data Outside the European Economic Area
Art. 12. (1) As a rule, personal data processed through the Platform are stored on servers located in the European Union (“EU”) / European Economic Area (“EEA”).
(2) Notwithstanding paragraph 1, in certain circumstances limited transfers of Personal Data outside the EEA may take place, including, but not limited to:
1. during technical support and administration by an infrastructure, hosting and storage provider or another technical provider whose contracting entity or personnel are outside the EEA, where access is necessary to resolve technical problems, provide support or administration, or ensure service continuity, including where data are stored in the EEA but the provider may be accessed from a jurisdiction outside the EEA;
2. during archiving, backup and disaster recovery operations;
3. when using analytics and advertising providers and software components embedded in the Mobile Application, or an address autocomplete, verification and geocoding service provider whose servers or parent companies may be outside the EEA;
4. when publishing content on social networks (Facebook, Instagram, TikTok, YouTube, LinkedIn, etc.), where applicable;
5. when sending messages through Viber, WhatsApp, Telegram, Signal or another instant messaging channel and delivering Push Notifications whose infrastructure, including the device operating system infrastructure, may include servers outside the EEA.
(3) Where a data transfer outside the EEA is necessary, the Company makes it only on the basis of a European Commission adequacy decision under Article 45 GDPR or appropriate safeguards under Article 46 GDPR, including standard contractual clauses adopted by the European Commission, or, in their absence, only on an applicable ground under Article 49 GDPR.
(4) The Company makes efforts to minimise transfers of data outside the EEA and, where possible, to limit access by personnel outside the EEA to Personal Data.
(5) You may obtain more information about the specific safeguards applied to transfers of data outside the EEA by contacting us at [email protected].
Cookies and Similar Technologies
Art. 13. (1) The Platform uses cookies and similar tracking technologies. Detailed information about the types of cookies, the purposes for which they are used, the ways to manage your preferences and your rights in relation to them is contained in a separate Cookie Policy, available at www.onecare.bg.
(2) In the Mobile Application, equivalent technologies for storing and accessing information on the device may be used instead of cookies, including device and installation identifiers and embedded software components. The Cookie Policy rules and the consent requirement, where applicable, apply accordingly to their use.
Personal Data Retention Periods
Art. 14. (1) The Company stores personal data for a period no longer than necessary to achieve the purposes for which the data are processed, taking into account the applicable statutory retention periods.
(2) The main retention periods are as follows:
1. User Account Data: for the lifetime of the account and up to 6 months after deletion. For Service Providers and associated persons, trader data necessary to trace transactions are retained for at least 6 months after termination of the relationship under Article 30, paragraph 2 of Regulation (EU) 2022/2065. A longer period applies where necessary to fulfil a legal obligation or defend legal claims;
2. Data related to a specific request and performance of a service - for a period of 5 years from the date of performance or termination of the contract for the service, in accordance with the general limitation period under the Bulgarian Obligations and Contracts Act;
3. Accounting and tax documents, including invoices and payment documents - for a period of 10 years, counted from 1 January of the year following the year to which they relate, in accordance with the Bulgarian Accountancy Act and the Tax and Social Security Procedure Code;
4. Medical documentation uploaded through the Platform by a Service Provider - the Company stores such documentation in its capacity as a Personal Data processor under the instructions of the Service Provider. Retention periods are determined by the Service Provider in accordance with the applicable health legislation;
5. Marketing Communication and Marketing Consent Data: until consent is withdrawn or the relevant communication is unsubscribed from; evidence of consent given, changed and withdrawn is retained for 5 years after withdrawal or unsubscription, for accountability and defence of legal claims;
6. Cookie data - in accordance with the periods set in the settings of the relevant cookie, but no longer than 2 years;
7. Communication data (forms, complaints, correspondence) - for a period of 5 years from the last communication, unless a longer period is necessary for the defence of legal claims;
8. Data of Service Providers and their professionals - for the duration of the contractual relationship between the Company and the Service Provider and for a period of 5 years after its termination;
9. Photographs and Video Materials: until consent is withdrawn, except for materials already lawfully published, indexed, archived or stored beyond the Company's actual control;
10. Telephone Call Recordings: for up to 6 months after the call, unless a particular recording is needed to consider a complaint, resolve a dispute or defend legal claims, in which case it is retained until their final conclusion;
11. Data on acceptance of the General Terms and Conditions and this Policy, the accepted version and the IP address: for the lifetime of the account and for 5 years after its termination, in accordance with the general limitation period under the Obligations and Contracts Act;
12. Data relating to notices of illegal content, measures imposed and internal complaints under Regulation (EU) 2022/2065: for 5 years after the relevant action, unless a longer period is necessary to defend legal claims or is ordered by a competent authority;
13. Online Consultation Recordings where made under legislation: for the period prescribed by applicable health legislation, with the Company retaining them as Controller subject to professional secrecy.
(3) After expiry of the applicable retention period, the Company deletes or anonymises the personal data, unless their storage is necessary for compliance with a legal obligation, for the defence of legal claims or on another applicable legal ground.
(4) The specific retention periods may vary depending on the type of service, the applicable legislation and the specific circumstances. Upon request, the Company provides information about the applicable retention period in respect of specific categories of data.
(5) The Company periodically reviews the necessity of storing Personal Data and the adequacy of the specified periods, taking into account legislative changes, the purposes of the Processing and the principle of data minimisation.
(6) User account deletion takes place in stages: some data are erased immediately, while data subject to a legal retention obligation or a ground for defending legal claims are retained until the relevant period expires with restricted access. During that period, the data are not used for purposes other than the purpose for which they are retained.
Rights of Data Subjects
Art. 15. (1) Pursuant to the GDPR and the applicable legislation, you have the following rights in relation to your Personal Data:
1. Right of access (Article 15 GDPR) - to obtain confirmation as to whether the Company processes your Personal Data and, where this is the case, to obtain access to them and to information about the Processing;
2. Right to rectification (Article 16 GDPR) - to request rectification of inaccurate Personal Data or completion of incomplete data;
3. Right to erasure (“right to be forgotten”) (Article 17 GDPR) - to request erasure of your Personal Data where the grounds provided for in the GDPR are present, except where the Processing is necessary for compliance with a legal obligation, for the establishment, exercise or defence of legal claims or on another ground provided by law;
4. Right to restriction of Processing (Article 18 GDPR) - to request restriction of Processing in the cases provided for by the GDPR;
5. Right to data portability (Article 20 GDPR) - to receive your Personal Data in a structured, commonly used and machine-readable format and to transmit those data to another controller, where the Processing is based on consent or on a contract and is carried out by automated means;
6. Right to Object (Article 21 GDPR): to object at any time to Processing of your Personal Data where based on the Company's legitimate interest. If you object to Processing for direct marketing, including In-Platform Messages with promotional content and related profiling, Processing for those purposes stops unconditionally;
7. Right not to be subject to a decision based solely on automated Processing, including profiling (Article 22 GDPR) - where applicable;
8. Right to withdraw consent - where the Processing is based on your consent, you have the right to withdraw it at any time, without affecting the lawfulness of the Processing carried out before the withdrawal.
(2) To exercise your rights under paragraph 1, you may send a request by email to [email protected]. The Company may request additional information to establish your identity before acting on the request. The User may request deletion of the account and related data through a functionality in the Mobile Application itself, a functionality on the website, a request to the Company at the specified email address without reinstalling the Mobile Application, or a publicly accessible website page allowing a deletion request without registration, account login or installation of the Mobile Application. The address of that page is published in the Platform and supplied to the relevant application store. Upon deletion, data collected during registration and use of the Platform, including profile, address, marketing and behavioural data, are erased; data subject to a legal retention obligation or a ground for defending legal claims are retained with restricted access for the periods under Article 14 and erased or anonymised upon their expiry.
(3) The Company responds to requests under paragraph 1 within 1 month of receipt. Where necessary, this period may be extended by up to two additional months, taking into account the complexity and number of requests, of which the Company informs the data subject. Where the request is made electronically, the information is supplied electronically unless the data subject requests otherwise.
(4) The exercise of the rights under paragraph 1 is free of charge. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the Company may charge a reasonable fee or refuse to act on the request.
(5) Where personal data are processed by the Company in its capacity as processor under the instructions of a Service Provider, the Company may forward the request to the relevant Service Provider, which is the controller of those data.
(6) The right to erasure and the right to be forgotten are exercised subject to the time limits and staged deletion procedure under Article 14, with data subject to a legal retention obligation or a ground for defending legal claims retained until the relevant period expires.
(7) Withdrawal of marketing consent and objection to direct marketing may also be exercised through the unsubscribe link in each relevant communication, Account settings and, for Push Notifications, the device's notification settings, without submitting a separate request.
Marketing Communications
Art. 16. (1) The Company may send marketing communications electronically, including by email, text message, Viber or another instant messaging channel and Push Notifications, to Users and Service Providers who have consented. Consent covers those channels and is given through a separate action that is not preselected. In the cases provided by law, the Company may send communications concerning its own similar services to existing customers on the basis of legitimate interest, providing an easy means of objection in every communication. Consent may be withdrawn at any time without affecting the lawfulness of Processing before withdrawal.
(2) Detailed information about types of marketing communications, channels, frequency, unsubscribe methods and your rights is contained in a separate Marketing Policy available in the Platform. Consent to marketing communications is given under Article 5 of the Marketing Policy through a separate action distinct from accepting the General Terms and Conditions and acknowledging the policies.
(3) The Marketing Policy forms an integral part of this Privacy Policy.
(4) Communications relating to an Order Request, payment, modification, cancellation, rescheduling, service status, appointment reminder, security, policy updates and other essential aspects of the legal relationship are not marketing communications and do not require separate marketing consent. These communications may be sent by email, text message, telephone call, Viber, WhatsApp, Telegram, Signal or another instant messaging channel, Push Notifications and In-Platform Messages specified by the User or used within the Platform.
(5) In-Platform Messages with promotional content are based on the Company's legitimate interest in direct marketing in connection with the Platform and the services and offers available through it, rather than consent. They are subject to the right to object under Article 15, paragraph 1, item 6 and Section X.
Security of Personal Data
Art. 17. (1) The Company applies appropriate technical and organisational measures to protect personal data against unauthorised or unlawful access, accidental loss, destruction, damage, alteration or disclosure, including, but not limited to:
1. encryption of data in transit (SSL/TLS) and at rest (AES-256 or an equivalent standard);
2. data backup;
3. monitoring, logging, access management based on granted permissions and security incident notification;
4. periodic review and update of security measures.
5. storing passwords only in irreversibly encrypted form;
6. pseudonymisation and data minimisation where applicable, including displaying ratings and reviews using initials only, without directly identifying data.
(2) The Company cannot guarantee absolute security of data, as no system for transmitting or storing data via the Internet is completely secure. In the event of a personal data breach, the Company notifies the competent supervisory authority and the affected data subjects in accordance with Articles 33 and 34 GDPR, where applicable.
(3) Users and Service Providers are obliged to keep their access credentials (username and password) confidential and to notify the Company immediately in the event of any suspicion of unauthorised access to their account.
(4) Where any Processing, in particular using new technologies or involving large-scale Processing of special categories of data, is likely to result in a high risk to the rights and freedoms of natural persons, the Company carries out a prior data protection impact assessment (DPIA) in accordance with Article 35 GDPR before commencing the Processing.
(5) The Company applies the principles of data protection by design and by default within the meaning of Article 25 GDPR, by integrating appropriate technical and organisational measures for the protection of Personal Data when designing and developing the Platform and by ensuring that, by default, only data necessary for each specific purpose are processed.
(6) The Company maintains a record of processing activities under Article 30 GDPR, which contains information about the purposes of the Processing, the categories of data subjects and data, the recipients, the retention periods and a description of the technical and organisational security measures.
(7) The Company ensures internal control over compliance with this Policy and the applicable Personal Data protection legislation, including through periodic internal checks, training of personnel with access to Personal Data and maintenance of documentation of the accountability activities carried out.
(8) The Company processes Personal Data in its own environment, maintained through the infrastructure providers under Article 11, paragraph 1, item 2, and in the environments of the other technical providers under that provision. The Company may change the composition of technical providers and allocation of operations among them over time according to the Platform's development, introduction of new functionalities, security requirements and applicable legislation; adding, replacing or removing a provider within a category and purpose described in Article 11, paragraph 1, item 2 does not constitute an amendment to this Policy.
(9) The Company does not store Health Data in consumer cloud services of the operating system provider or another third party intended for the data subject's personal use. The Mobile Application does not use operating system health data interfaces and does not read data from health applications on the device. If such functionality is introduced, it is used only after separate permission and solely for the purpose expressly stated to the User, and data obtained through it are processed subject to Article 10, paragraph 5.
Allocation of Roles Between the Company and the Service Provider
Art. 18. (1) The Platform acts as an online marketplace and intermediary between the User and the Service Provider. The allocation of roles with respect to the Processing of Personal Data is as follows:
1. The Company is an independent controller for the registration and maintenance of user accounts, its own general terms and policies, its own accounting, tax and legal servicing, the security and functioning of the Platform, marketing communications, analytics and any other operation for which it independently determines the purposes and means of the Processing;
2. The Service Provider is an independent controller for the provision of the service itself, the medical or other professional assessment, the creation and storage of medical and other professional documentation, the fulfilment of obligations to regulatory authorities and any other operation for which it independently determines the purposes and means;
3. The Company is a Personal Data Processor on behalf of the Service Provider for technical receipt and routing of Order Requests, hosting and storage of documents, storage of Online Consultation recordings where made on the Service Provider's instructions, issuing invoices on the Service Provider's behalf, Processing payments on the Service Provider's behalf and other operations where the Company acts on the Service Provider's instructions;
4. For certain operations where the Company and the Service Provider jointly determine the purposes and essential means of Processing (e.g. e.g. managing the process of ordering, confirming and tracking an Order Request, access to to documents, an integrated invoicing and payment process), they may act as joint controllers within the meaning of Article 26 GDPR, with the internal allocation of responsibilities governed by a separate agreement.
(2) The specific allocation of roles between the Company and each individual Service Provider is governed by a data protection agreement, which forms an integral part of the contractual relationship between them.
(3) Irrespective of the internal allocation of roles, the data subject may exercise his or her rights against each of the parties, insofar as this is permitted by the applicable legislation.
(4) Where legislation requires an Online Consultation recording to be made and retained, the Company is an independent controller of that recording insofar as it independently determines the means of storing and protecting it, subject to professional secrecy and applicable health legislation.
Protection of Children’s Personal Data
Art. 19. (1) The Platform is intended for persons aged 18 or over. Persons under 18 may not register, create an account or independently order services through the Platform.
(2) Upon registration, the User declares that they are at least 18 in accordance with Article 4, paragraph 2. The Company does not knowingly collect data of persons under 18 registered as Users.
(3) The User may order a service for a Service Recipient who is a child or minor in their capacity as parent, guardian, custodian or other legal representative, or with the knowledge and consent of such a person, acting on the person's behalf and bearing responsibility for the lawfulness of providing the data under Article 9 of the General Terms and Conditions.
(4) Where a service for a child or minor requires Processing of Special Categories of Personal Data, including Health Data, Processing takes place on the basis of Article 9, paragraph 2, point (h) in conjunction with Article 9, paragraph 3 GDPR, or, where that basis does not apply, on the basis of express consent of the parent or legal representative under Article 9, paragraph 2, point (a) GDPR.
(5) If the Company establishes that a person under 18 has registered or provided their own data as a User without proper grounds, it takes steps to erase those data as soon as possible.
Right to Lodge a Complaint
Art. 20. (1) If you consider that the Processing of your Personal Data infringes the GDPR or the applicable personal data protection legislation, you have the right to lodge a complaint with:
1. the Commission for Personal Data Protection (CPDP) - address: Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd.; website: www.cpdp.bg; email: [email protected];
2. a supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement, where applicable.
(2) The right to complain does not depend on first exercising the rights under Section X of this Policy, but the Company encourages you to contact us first at [email protected] or [email protected] so that we can resolve the matter.
(3) Where a complaint concerns the Company's obligations as a provider of intermediary services under Regulation (EU) 2022/2065, the competent authority is the Communications Regulation Commission as Digital Services Coordinator for the Republic of Bulgaria, without affecting the Commission for Personal Data Protection's competence in data protection matters.
Amendment of the Privacy Policy
Art. 21. (1) The Company has the right at any time to amend, supplement or replace this Policy, including in the event of changes to the applicable legislation, technical and organisational conditions, categories of data processed, providers or functionalities of the Platform.
(2) The current version of the Policy is published on the Platform at www.onecare.bg, indicating the date of the latest update.
(3) In the event of material changes affecting data subjects' rights, the Company notifies Users and Service Providers by email, In-Platform Message, Push Notification or another appropriate means before the change takes effect. Where an amendment requires consent, the change takes effect for the relevant Processing only after consent is given.
(4) Continued use of the Platform after the amendment enters into force shall be deemed acknowledgement of the current version of the Policy, insofar as this is permitted by the applicable legislation.
(5) Adding, replacing or removing a technical provider, communication channel, device permission or functionality within a Processing category and purpose already described in this Policy does not constitute an amendment to it. Such changes are reflected in the Platform and do not require separate notice unless applicable legislation requires otherwise.
Final Provisions
Art. 22. (1) This Policy has been adopted by the Company's manager and enters into force as of 16.09.2026. It repeals and replaces all previous versions of the Privacy Policy.
(2) Matters not governed by this Policy are subject to applicable legislation, the General Terms and Conditions for Use of the OneCare Platform, the Cookie Policy and the Marketing Policy.
(3) The invalidity of an individual provision of this Policy shall not result in the invalidity of the remaining provisions.
(4) This Policy is drawn up in Bulgarian. The Bulgarian version is the original and the only legally binding version. Any version in another language, including one prepared through automated translation, is for information only and for the convenience of the person concerned; in the event of any discrepancy, conflict or doubt as to meaning, the Bulgarian version applies, and a version in another language does not create rights and obligations different from those provided for in the Bulgarian version.