Privacy Policy
Last updated: August 2026
Translation notice
This document is an English translation of the Greek original, "ΠΟΛΙΤΙΚΗ ΠΡΟΣΤΑΣΙΑΣ ΠΡΟΣΩΠΙΚΩΝ ΔΕΔΟΜΕΝΩΝ DOCNOW" (August 2026). It is provided for convenience only and has no independent legal effect. The Greek text is the sole binding and authoritative version, and in the event of any discrepancy, ambiguity or conflict between the two, the Greek text prevails.
1. DOCNOW E.E.
The limited partnership under the name "DOCNOW E.E." (hereinafter the "Company"), having its registered seat at Nea Ionia, Attica, 3-5 Evangelikis Scholis Street, has as its purpose the provision of services to third parties as follows: 1. The creation from scratch of a telemedicine platform, 2. The repair of an existing platform or the upgrading thereof, 3. The creation of electronic advertising, 4. Automated email dispatch services on behalf of the company or its clients, 5. Market research services relating to the above, 6. Advertising services in media independent of the above, 7. Consultancy services. And any purpose related to the above. For the fulfilment of its purpose, the company may establish branches in Greece and abroad and may participate in, as well as cooperate with, any other undertaking abroad or domestically having the same or a similar purpose. It is also entitled to develop any other activity connected with the above purposes, in respect of which the individual objectives and actions are listed by way of example and not exhaustively. Within the framework of the above purposes, DocNow operates a telemedicine platform through which Users schedule and conduct video consultations with a certified doctor.
In this context, it collects and processes personal data of partner doctors, users, partners and suppliers in those cases where this is required for the fulfilment of its contractual obligations, observing the principles set out in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "GDPR"), as well as the applicable national and European legislation on the protection of personal data. It also takes all appropriate technical and organisational measures required for the protection of the personal data it collects and processes.
2. Scope
This Personal Data Protection Policy (hereinafter the "Protection Policy") sets out the terms and conditions observed by the Company for the protection of the personal data of the data subjects whose data are processed. The purpose of this Policy is to inform as to the personal data which the Company collects and processes, as well as as to the manner and the purposes for which it collects, stores, uses and transmits such personal data as applicable, and further to inform data subjects as to the rights they have under applicable law. The Company reserves the right to amend, update and revise this Policy from time to time, where this is deemed necessary and in accordance with the legislation in force at the relevant time.
As regards the use of specific personal data protection terms, the provisions of Article 4 GDPR apply.
The remaining terms referred to in this Policy have the meaning defined in the GDPR and in national legislation concerning personal data.
3. Sources of data collection
Personal data are collected from the data subject itself, or from a person authorised by it. The Company does not collect data from other third-party sources, save in those cases where it is authorised by the data subject specifically for the particular processing.
4. Data subjects and categories of personal data processed
The categories of data subjects whose personal data the Company processes are:
i. Users: Identification and contact details (e.g. full name, address, telephone, email, etc.), call recording where consent exists, financial data (e.g. IBAN, invoices).
ii. Doctors: Unique identifiers (e.g. Tax Registration Number, ID card number, etc.), Identification and contact details (e.g. full name, address, telephone, email, etc.), Financial data (e.g. IBAN, invoices).
iii. Suppliers & Partners: Unique identifiers (e.g. Tax Registration Number, ID card number, etc.), Identification and contact details (e.g. full name, address, telephone, email, etc.), Financial data (e.g. IBAN, invoices).
5. Purposes and legal bases of processing
The Company processes the personal data of the above natural persons only where it has a lawful reason to carry out the relevant processing. Accordingly, it processes personal data for the purposes and on the lawful grounds set out below in accordance with points (b), (c) and (f) of Article 6 of Regulation 2016/679, and specifically where the processing is necessary:
i. For the purposes of the legitimate interests pursued by the Company as Controller, the performance of contracts, the fulfilment of its contractual obligations and the exercise of its rights, such as, by way of example, for the issuance of tax documents to suppliers and partners, the administration of employee payroll, etc.
ii. For the purposes of carrying out the obligations and exercising specific rights of the Company as controller or of the data subject in the field of employment law and social security and social protection law, such as, by way of example, for the social insurance of employees.
iii. For the establishment, exercise or defence of legal claims.
iv. For the performance of contracts, the fulfilment of its contractual obligations and the exercise of its rights as Processor.
a. The Company processes the personal data it collects lawfully and fairly. It neither collects nor processes a greater quantity of information or data than that required for the fulfilment of the purposes of the processing. The collection and processing of the data of natural persons is carried out exclusively for the purposes of processing referred to above. The data are also stored in a physical file at the offices of the company. All of the company's systems are designed so as to safeguard and protect personal data.
Where data subjects express a wish to enter into a contract, the company transmits the personal data to the company for which it has undertaken the promotion of products and services. The company also processes and collects the personal data of clients who give their express consent to this, without entering into a contract.
Energy / mobile telephony services
6. Categories of recipients of personal data
The Company may, as applicable, transmit the personal data of natural persons to banks, public services and public bodies, as well as to processors acting on its behalf (such as, by way of example, software and application providers, accounting support firms, legal advisers, etc.). Transmission is effected exclusively for the purposes described herein and always on condition that the above-mentioned persons accept and comply with the terms of this Policy and of the legislation. In such cases the Company remains responsible for the processing of the personal data and ensures that the processing is carried out in accordance with the applicable legal framework and that every natural person may exercise their rights under applicable law. The company ensures that its partners observe the requirements of the legislation and comply with the GDPR, monitoring their actions through the Active Directory (A.D.) service.
7. Retention period of personal data
The period for which data are stored is determined on the basis of the following specific criteria, as applicable:
a. Where processing is carried out pursuant to a relevant contract, personal data are stored for such period as is necessary for the performance of the contract and for the establishment or exercise of rights and/or the support of legal claims which may arise from it, or for the defence of rights before Courts, Judicial Authorities, etc.
b. Where processing is carried out for tax purposes, personal data are stored for a period of thirty (30) years.
c. Where processing is carried out on the basis of the data subject's consent, the data are retained for as long as the data subject's consent remains in force, or as is required for the establishment or exercise of rights and/or the support of legal claims which may arise from it, or for the defence of rights before Courts, Judicial Authorities, etc., or as the relevant provisions require or permit.
d. Records of telephone communications are retained for a period of 2 years from the last communication, unless their retention is requested by the client in respect of the data concerning them, or by the General Secretariat for Consumer Affairs for the purpose of verifying compliance with the provisions of Law 3758/2009 (Article 6).
e. In any event, sensitive personal data are not retained for longer than twenty (20) years from the last consultation, pursuant to Law 3418/2005, Code of Medical Ethics (Article 14).
8. The rights of data subjects
Every natural person whose data are the subject of processing by the Company enjoys the following rights, which are subject to limitations depending on the type of personal data, the purpose and the legal basis of the processing.
Every data subject has the right to obtain information from the Company, confirmation as to whether or not personal data concerning them are being processed and, where that is the case, has the right of access to the personal data.
Every data subject has the right to request the rectification, completion and updating of their data.
Every data subject has the right to request the erasure of their personal data where the processing is carried out on the basis of their consent, by withdrawing it. In the remaining cases (such as, by way of example, where there is a legal obligation of the Company, the exercise of official authority, an obligation to process personal data imposed by law or by the public interest, or for the establishment, exercise or support of legal claims), the said right is subject to specific limitations or does not exist, depending on the case.
Every data subject has the right to request the restriction of the processing of their personal data where:
Every data subject has the right to object at any time to the processing of their personal data where such processing is necessary for the purposes of the legitimate interests pursued by the Company as controller.
Every data subject has the right to receive their personal data in a format which permits access to them. The said right applies to data which have been collected from the data subject and the processing of which is carried out by automated means on the basis of consent or for the performance of a contract.
The data subject has the right to withdraw their consent at any time by sending the relevant request to the email address privacy@docnow.gr.
Data subjects have, in the event of a breach, the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr).
9. Security of personal data
The Company has taken and applies all appropriate technical and organisational measures with the aim of ensuring the secure processing of personal data and preventing accidental loss or destruction, unauthorised and/or unlawful access, use, alteration or disclosure, and takes care as to the lawfulness of the collection and processing and the secure retention of personal data, in accordance with the provisions of national, European and international law concerning the protection of individuals with regard to the processing of personal data, and in particular having regard to the provisions of the GDPR.
10. DPO contact details
For any information relating to the processing of personal data or the exercise of any of the above rights, data subjects may address themselves to the Data Protection Officer, Emmanouil I. Laskaridis, by sending their request to the email address privacy@docnow.gr.
11. Right to lodge a complaint with the HDPA
Data subjects retain the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr): Telephone Centre: 210 6475600, Fax: 210-6475628, Email: complaints@dpa.gr.
This is an English translation provided for convenience. The Greek original is the sole binding version and prevails in the event of any discrepancy. Acceptance takes place within the DocNow app.