Privacy Policy
minus10med processes personal data under the EU General Data Protection Regulation. We collect only what a consultation, booking or enquiry requires, we store health data inside the EU, we encrypt it in transit and at rest, and we never sell it or use it for advertising or profiling.
Who is responsible for your data?
The data controller is minus10med, a longevity medicine practice operating in Athens, Greece. Clinical visits take place at our partner clinic, Notia MedCare in Glyfada, which acts as an independent controller for the medical records it creates in the course of care it delivers. Questions about this notice can be sent to hello@minus10med.com, and the postal address and phone number are on the contact page.
What personal data do you collect?
We collect three categories, and nothing beyond them.
- Contact data. Name, email address, phone number and the free text of the message you send us, whether by email, by phone or through the appointment form.
- Booking data. Name, email address and the time slot you select in the embedded calendar, for the sole purpose of holding your appointment.
- Health data. Laboratory results, imaging reports, questionnaires, medication lists and clinical notes, collected only once you become a patient and only where they are needed for the assessment or therapy you have agreed to.
Aggregate page views are always measured with a cookieless, EU hosted analytics tool that stores no cookies and no personal data, and cannot identify an individual visitor. In addition, a second measurement tool, Google Analytics 4, is available but stays switched off unless you actively turn analytics on using the toggle in the site footer, under Analytics measurement. Consent is denied by default, advertising and profiling storage stay denied at all times, and nothing is written to your device while consent is denied. You can withdraw the permission at any moment with the same toggle. We set no marketing or advertising cookies in any state.
What is the lawful basis for processing?
Contact and booking data are processed on the basis of your request, that is, steps taken at your request before entering a contract, and our legitimate interest in replying to enquiries. Health data is special category data under Article 9 of the GDPR and is processed for the purposes of preventive medicine, medical diagnosis and the provision of health care by, or under the responsibility of, a physician bound by professional secrecy. Where processing goes beyond that, for example a research use or a marketing message, we ask for explicit consent first, and you can withdraw it at any time.
How long is data kept, and where?
Enquiry correspondence that does not become a patient file is deleted within twelve months. Booking records are deleted within twelve months of the appointment. Medical records are retained for the period required by Greek medical record keeping law, which is longer than the periods above and applies regardless of whether you continue as a patient.
Data is stored on infrastructure located in the European Union. Where a processor operates outside the EU, we use a provider offering an EU region and standard contractual clauses. We do not transfer health data outside the European Economic Area for routine operations.
How is data protected?
Communications with patients and customers are protected by end-to-end encryption, with data encrypted in transit and at rest. Access is limited to the clinicians and administrative staff who need it for your care, each with an individual account. Laboratory and imaging partners receive only the identifiers required to perform and return the test you have consented to. Details of the AI tooling that touches website text, and the strict limits placed on it, are set out on the AI use and data handling page.
What rights do you have, and how do you exercise them?
Under the GDPR you may request access to your data, correction of inaccurate data, erasure where no legal retention duty applies, restriction of processing, portability of data you provided to us, and objection to processing based on legitimate interest. Send the request to hello@minus10med.com and we reply within one month. If you are not satisfied, you may complain to the Hellenic Data Protection Authority, the supervisory authority for Greece.