Privacy Policy

Effective date: May 28, 2026

Administrator of Personal Data

The Administrator of your personal data is Klinika Krejcárek s. r. o., Identification No. 19422784, with its registered office at Prosecká 876/89, Prosek, 190 00 Prague 9, Czech Republic, entered in the Commercial Register administered by the Municipal Court in Prague, Section C, File 386014 (hereinafter referred to as the "Administrator" or "OpenMedical").

OpenMedical (openmedical.cz) is the brand under which the Administrator provides a paid membership and care-navigation service. OpenMedical is not a healthcare provider and does not itself perform medical examinations, diagnoses, treatment, or clinical consultations.

The Administrator is the controller of personal data processed for membership, scheduling, coordination of appointments, communication with partner providers on the client's behalf, payment handling, follow-up reminders, and related administrative support.

This notice describes the maximum scope of processing under the service. At launch, processing is limited to membership administration, scheduling and coordination of in-person appointments at partner providers, communication with the client by phone (including call recording under the conditions described in the "Telephone calls and call recording" subsection below) and e-mail, payment handling, and related administrative tasks. The following capabilities and channels are not yet live and the related processing only begins once each goes live, with this notice updated before it does: the mobile app and client account, the later web client portal, secure in-product messaging and document uploads, AI-assisted support tools, telehealth coordination at partner providers, employer-linked and family programmes, clinical studies and research, and WhatsApp and Telegram channels. Where any of those capabilities requires additional consent (in particular for health-related context or telemedicine), that consent will be collected separately at the point of activation.

All medical care is provided by separately licensed partner clinics, hospitals, laboratories, and individual healthcare professionals. Each such partner is an independent controller for the personal data, including health data and medical records, that they create and process when delivering care.

Where, in order to navigate or schedule care appropriately, the client shares health-related information with the Administrator, that information is special-category data under Article 9 GDPR and the Administrator requires the client's explicit consent for it. Processing is limited to what is necessary for the navigation purpose; the detailed legal basis is set out below in the "Why Do We Process Your Data and What Is the Legal Basis?" section.

Introductory Information

This document serves several purposes. You will learn which of your data we process and why, what rights you have in connection with personal data processing, and to whom you can turn with your questions, suggestions, or complaints. We ask that you read the following text carefully. It is divided into sections so that you can easily find the information relevant to you.

If anything is unclear to you regarding the protection of personal data, please do not hesitate to contact us.

For general privacy questions and clarification of this Policy, use the general privacy contact below. To exercise GDPR rights, submit formal requests, complaints, or other data-protection submissions, use the privacy contact point in the following subsection.

  • Postal: Klinika Krejcárek s. r. o., Prosecká 876/89, Prosek, 190 00 Prague 9, Czech Republic
  • By e-mail at: privacy@openmedical.cz

Privacy Contact

To exercise GDPR rights, submit formal requests, complaints, or other data-protection submissions, please use the privacy contact point below. We have not formally designated a Data Protection Officer (DPO) under Article 37 GDPR at this time. If the scope of our processing makes the appointment of a DPO mandatory under Article 37(1) GDPR, we will appoint one, notify the Czech Office for Personal Data Protection (ÚOOÚ), and update this Policy accordingly. You can contact us using the following methods.

  • Postal: Klinika Krejcárek s. r. o., Prosecká 876/89, Prosek, 190 00 Prague 9, Czech Republic
  • By e-mail at: privacy@openmedical.cz

Supervisory Authority

The supervisory authority for personal data protection in the Czech Republic is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), located at Pplk. Sochora 27, 170 00 Prague 7. Current contact information is available at www.uoou.cz. You have the right to file a complaint with this authority at any time.

Basic Principles of Personal Data Processing

  • We process your personal data lawfully, fairly, and in a transparent and comprehensible manner.
  • We process your personal data only to the extent necessary and in a manner consistent with the purpose for which it was collected.
  • We take care to ensure that the personal data we process is accurate and kept up to date. Inaccurate data is corrected or deleted.
  • We process your personal data only for the period strictly necessary. In some cases this period is set by law; in others we define it internally in line with our legitimate interests.
  • We secure your personal data against leakage, unauthorised processing, accidental loss, and damage. We apply appropriate technical and organisational measures, including strict access controls, encryption, logging, and physical security.

Which of Your Data Do We Process?

Because each client uses our service in their own way, the list below describes the maximum set of data we may process in relation to you. We obtain your personal data directly from you, including documents and context you choose to share with us, and, with your consent, from partner providers as part of scheduling or coordinating your care.

Identification data

Name, surname, date of birth, birth-registration number (rodné číslo), insurance type (including Czech statutory public health insurance: VZP, VoZP, ČPZP, OZP, ZPŠ, ZPMV ČR, or RBP), public health insurance policyholder number, health-insurance provider code, identification document data where required, and your OpenMedical client account identifier.

Insurance information is collected and kept up to date so that we can split clinic services correctly between public-insurance-covered items and self-paid items, prepare or collect standard documents you may choose to submit to your commercial insurer for your own reimbursement request, coordinate care with the right partner providers, and handle billing correctly. OpenMedical does not decide coverage, submit claims, negotiate reimbursement, or act as an insurer, broker, or claims handler. Where you notify us of a change in your insurance during the membership year, we update your record accordingly and reassess clinic-side billing and reimbursement-document handling under our Terms of Service.

Contact data

Address of permanent residence, correspondence address, telephone number, e-mail address, data box ID, and preferred language of communication.

Data generated through the client portal and digital channels

Appointment records and reminders, documents you upload to share with partner providers, messages exchanged through secure messaging, audit logs of access to your account and uploaded documents, consent records, and profile settings. OpenMedical does not currently coordinate telehealth consultations at partner providers. If such coordination is launched in the future, those sessions and any recordings will take place on the partner provider’s systems under the partner’s legal basis; OpenMedical does not store telehealth recordings.

Images and documents

Photos of documents you upload, for example prior medical reports and referrals, images captured during examinations, and imaging studies.

Billing and payment data

Data necessary to bill the membership and coordination service to you directly or to your employer where applicable, including transaction identifiers. We do not store full payment card numbers; these are handled by certified payment providers.

Technical data

IP address, device and browser information, log data, and cookies, collected when you use openmedical.cz or the client portal. Details are provided in our Cookie Policy.

Other personal data

Recordings of telephone calls with our team (both inbound and outbound) captured via the CloudTalk cloud platform, including the call content, metadata (timestamp, duration, telephone numbers, operator identifier), and the related operator notes. You are informed of the recording at the start of each call and may request a non-recorded call. Details of the purpose, legal basis, and retention period are set out in the "Telephone calls and call recording" subsection below.

Communications you send us through website chat, WhatsApp, Telegram, or other messaging channels you choose to use.

In What Form Is Your Personal Data Processed?

Personal data we process for the membership and coordination service is held in our secure systems, primarily in electronic form. Access is limited to authorised staff (support, coordinators, administration) based on their role and is logged. Health-related context you share with us for navigation, including any documents you upload, is encrypted in transit and at rest, and access including downloads is auditable.

We do not maintain medical documentation. Medical documentation is created and held by partner healthcare providers who deliver your care, under their own legal duties (in the Czech Republic, in particular Act No. 372/2011 Coll. and Decree No. 98/2012 Coll.).

Production (live) and non-production (testing, development) environments are strictly separated, and real client data is not used in non-production environments.

Minors

OpenMedical membership is currently offered to natural persons aged 18 and over; we do not establish client accounts for minors at this time. If family or pediatric coordination becomes available, this section will be updated with the applicable guardian, consent and access rules before any minor data is collected.

Access to Records After the Client’s Death

Two separate paths apply when a client dies, because medical documentation and the data we hold for the membership service sit with different controllers.

Medical documentation held by partner providers

Inspection of, and copies from, the deceased client’s medical documentation is governed by Section 33 of Act No. 372/2011 Coll. Close persons (spouse, registered partner, parent, child, sibling, partner, and other persons the client identified as close during their lifetime) have the right to inspect that documentation unless the client expressly prohibited disclosure to specific persons during their lifetime. Because that documentation is held by partner providers, requests for it should be addressed to the partner provider that delivered the care. We will, on request, help identify the relevant partner.

Membership and coordination data we hold

For the data we hold ourselves (the client account, scheduling history, communications with our team, billing records, and any health-related context the client shared with us for navigation), close persons may request access to the extent permitted by law and by any instructions the client left with us during their lifetime. Such requests should be sent by post, in person, or by another secure channel agreed with us. We may require proof of identity and proof of the requester’s relationship to the deceased, for example a birth or marriage certificate, or a sworn declaration where the law allows.

Client’s lifetime instructions

During their lifetime, the client may name persons who are entitled to access data we hold, or, conversely, exclude specific persons. Such instructions are recorded in the client account and applied when handling requests after the client’s death.

Limits on disclosure

Information that the deceased client expressly prohibited from disclosure, and information whose disclosure would breach the legitimate interests of third parties, may be withheld in line with the law. The right of close persons does not extend to data outside the categories named above, except where another statutory basis applies.

To Whom Can We Transfer Your Personal Data?

As a rule, we process your personal data within OpenMedical. In certain cases, however, we may transfer your data to other recipients.

State authorities and public bodies

We may disclose data where we are legally obliged to do so, for example to courts, law enforcement, or other public authorities within the limits of the law.

Partner clinics and specialist providers

OpenMedical coordinates care delivered by a network of partner clinics, hospitals, laboratories, and specialist providers. Where you proceed to receive care from a partner, for example for a consultation, an imaging study, or a laboratory test, we share the data necessary to schedule and refer you, including any health-related context you have shared with us for that purpose.

Each partner provider is an independent controller for the personal data and medical documentation they create and process when delivering care. Partner providers are bound by their own healthcare confidentiality and data protection obligations under Czech and EU law. In specific pathways where OpenMedical and a partner jointly determine how data is processed, the relationship may be structured as joint controllership under Article 26 GDPR, and you will be informed accordingly.

Some partner clinic premises may operate CCTV for safety and security. In that case the partner clinic is the controller for the camera footage and provides its own information notice and signage at the location.

Insurance and assistance partners

Where you choose a programme that includes a partner-managed insurance or assistance benefit (for example a travel-insurance or worldwide medical-assistance benefit), or ask us to activate such a benefit, we may share the personal data necessary to activate and administer that benefit. This usually includes identification, contact, membership, and eligibility data. The current provider is named in the programme description on our website and may change from time to time.

We share health-related context with an insurance or assistance partner only where it is necessary for the requested benefit or claims handling and only with the applicable legal basis, including explicit consent where required. The insurance or assistance partner acts as an independent controller for its own benefit administration, assistance handling, and claims handling under its own terms and privacy information.

Processors acting on our behalf

This includes providers of IT infrastructure, hosting and protected storage, the client portal and operations platform, secure messaging, document management, identity verification, notifications, audit logging, payment processing, customer support tools, analytics, and advertising and conversion measurement. All processors are bound by written data processing agreements and are selected under strict criteria. OpenMedical does not allow processors to use your data for their own purposes.

For our public-facing services (the website, the contact form, subscriber emails, and our business email) we currently rely on the following named sub-processors. If an additional processor is introduced in the future (for example a scheduling tool or analytics platform), this notice will be updated and the new processor will be named here with its country and transfer basis before any related processing begins.

  • Hetzner Online GmbH (Germany, EU): hosting of the website and the contact-form backend.
  • Cloudflare, Inc. (United States, under the EU-US Data Privacy Framework and Standard Contractual Clauses): authoritative DNS, reverse proxy, and DDoS protection for openmedical.cz; all web traffic passes through Cloudflare's edge network, where TLS is terminated, traffic is filtered, and bot protection is applied.
  • Google LLC, Google Workspace (United States, under the EU-US Data Privacy Framework and Standard Contractual Clauses): business email used to receive and reply to your enquiries.
  • UAB MailerLite (Lithuania, EU): delivery of subscriber and notification emails.
  • CloudTalk s. r. o. (Slovak Republic, EU): cloud telephony platform, call recording, operational customer-support, and contact records associated with telephony, including callbacks and operator notes related to phone calls. For voice routing and recording storage, CloudTalk may rely on sub-processors located outside the EEA (in particular Twilio Inc. and Amazon Web Services, Inc. in the United States) under the EU-US Data Privacy Framework, Standard Contractual Clauses approved by the European Commission, and supplementary measures.
  • Google LLC, Google Tag Manager, Google Analytics, and Google Ads (United States, under the EU-US Data Privacy Framework and Standard Contractual Clauses): consent-gated tag management, website analytics, advertising, and conversion measurement, only if you have given the relevant analytics or marketing consent via our cookie banner.

Google's role for third-party tags and measurement

When Google Tag Manager is loaded after consent and Google tags are used through it (Google Analytics 4 and Google Ads), Google also processes a limited set of data on its own infrastructure for its own purposes, in particular network security, fraud prevention, and the development and evaluation of advertising systems. To that extent Google acts as an independent controller under Article 4 GDPR, or as a joint controller under Article 26 GDPR where the purposes are determined jointly with OpenMedical.

For processing carried out solely on OpenMedical's behalf (for example delivery of a specific measurement event that we have configured), Google acts as a processor under Article 28 GDPR. The website analytics layer is limited to allowlisted interaction events and does not send names, e-mail addresses, telephone numbers, free-text enquiry messages, health-related context, or raw submitted form values to Google tags. This subsection does not apply if you have not consented to analytical and marketing cookies; in that case no related Google tag-side processing takes place.

You may exercise your GDPR rights in relation to Google's independent or joint controllership directly with Google under its privacy information available at policies.google.com/privacy; for the remainder you contact OpenMedical.

Your employer or corporate client

This applies only where you are enrolled in an employer-linked programme and only to the extent you have agreed to. Employers do not receive your medical data without your explicit consent.

Family members or household members

This applies only where you are enrolled in a family or household account and have explicitly agreed to the applicable access arrangements.

Transfers outside the EEA

We generally do not transfer your medical and client data outside the European Economic Area (EEA). Where any processor is located outside the EEA, or where a sub-processor provides services from outside the EEA, such transfer takes place only under the safeguards required by the GDPR, in particular Standard Contractual Clauses and supplementary measures, and, for health data, only where strictly necessary.

If you consent to analytical or marketing cookies on openmedical.cz, Google Tag Manager may load Google Analytics 4 or Google Ads tags and certain data associated with those cookies, such as your IP address, cookie identifiers, and allowlisted interaction events, is transferred to Google LLC in the United States. This transfer takes place under Google’s certification to the EU-US Data Privacy Framework and Standard Contractual Clauses approved by the European Commission. Details are available in our Cookie Policy.

Emails you exchange with our business addresses are processed via Google Workspace, which Google LLC operates from the United States. This transfer takes place under Google’s certification to the EU-US Data Privacy Framework and Standard Contractual Clauses approved by the European Commission.

Where MailerLite uses sub-processors outside the EEA for delivery of marketing emails, those transfers take place under Standard Contractual Clauses approved by the European Commission.

All communication between your device and openmedical.cz passes through the edge network operated by Cloudflare, Inc., which runs global infrastructure including data centers in the EU and the United States. In doing so, Cloudflare processes your IP address, request headers, and other technical data for TLS termination, attack mitigation, bot detection, and content delivery. The transfer may include processing in the United States under Cloudflare's certification to the EU-US Data Privacy Framework and Standard Contractual Clauses approved by the European Commission.

Telephone calls with our team and the related contact records are processed by CloudTalk s. r. o., headquartered in the Slovak Republic (EU). For voice routing and recording storage, CloudTalk may rely on sub-processors located outside the EEA, in particular Twilio Inc. and Amazon Web Services, Inc. with infrastructure in the United States. Those transfers take place under the EU-US Data Privacy Framework, Standard Contractual Clauses approved by the European Commission, and the supplementary measures described in the CloudTalk data processing agreement.

How Long Do We Retain Your Personal Data?

Your personal data is retained only for the strictly necessary period.

  • Contact-form enquiries that do not lead to a client relationship are retained for up to 12 months from your last interaction with us, then deleted.
  • Client account data, scheduling records, and communications are retained for the duration of your client relationship and for 4 years after it ends, so we can defend any legal claims. This reflects the general three-year limitation period under Section 629(1) of Act No. 89/2012 Coll. (the Civil Code) plus a short buffer. Individual records may be retained for up to 10 years where the absolute objective limitation under Section 629(2) is relevant to a specific dispute.
  • Health-related context you shared with us for navigation is deleted or anonymised within 30 days of (a) the navigation purpose ending, (b) withdrawal of your consent under Article 9(2)(a) GDPR, or (c) termination of your account, whichever is sooner. Where a specific legal claim is pending, the records needed for that claim are retained until the claim is finally resolved and for one year thereafter.
  • Marketing-consent records and contact data used for marketing are retained for 3 years from your last interaction with our marketing emails, or until you withdraw your consent, whichever is sooner.
  • Telephone call recordings and the related operator notes are retained for 12 months from the call date and then deleted. Where a dispute, complaint, or legal proceeding is pending in relation to a specific call, the relevant recordings are retained until the matter is finally resolved and for one year thereafter.
  • Records of unsubscribes and Article 21 objections are retained on two layers: (a) the active subscriber and unsubscribe record on MailerLite, our email service processor, under its own processor terms; and (b) in our own internal records, a minimal entry consisting of the sha256 hash of the lower-cased email address together with a timestamp, retained for as long as we operate any marketing list. Without this hashed entry we would not be able to reliably honour your preference if we later change email service provider.
  • Records evidencing your consent are retained for the duration of the relevant processing and for 3 years after consent ends, so we can demonstrate compliance with Article 7(1) GDPR.
  • Audit and access logs are retained for 12 months. Security-incident and authentication logs are retained for up to 24 months, in line with our obligations under Articles 5(2) and 33 to 34 GDPR and applicable Czech cybersecurity legislation.
  • Billing and accounting records are retained for up to 10 years, as required by Czech tax and accounting legislation.
  • Medical documentation is held by partner providers, not by OpenMedical, and is retained by them for the periods required by Decree No. 98/2012 Coll. and related legislation (typically 5 to 100 years depending on the type of record, or up to 10 years from the patient’s death).
  • Cookies and technical data are retained in accordance with our Cookie Policy.

What happens when your client relationship ends

When you terminate your client relationship with OpenMedical, or we terminate it in line with our Terms of Service, the following applies. Before the client account is deactivated, you can request a final export of your account data and download any documents you have uploaded to the portal. The client portal remains accessible for a 30-day transition period after termination, during which you can complete any outstanding downloads or requests; we will confirm the exact timing in writing.

After the transition period, the portal login is closed and active processing of your account stops. Communications and account data are retained for the legal periods set out above and then deleted or anonymised. Copies of medical documentation held by partner providers must be requested directly from those providers under the rules of Section 65 of Act No. 372/2011 Coll.; we will, on request, help you identify the relevant partner.

Your Rights in Relation to Personal Data

As a data subject, you have a range of rights under the GDPR in relation to the data we hold about you for the membership and coordination service. You should provide accurate identification and contact data so we can deliver that service. Where you choose to share health-related context with us for navigation, you may withdraw your consent at any time. Rights you wish to exercise in relation to medical documentation held by a partner provider are exercised at that partner provider, under the rules described elsewhere in this policy.

Right of Access

You have the right to know what data about you we process, for what purpose, for how long, where it was obtained, and to whom it is transferred. Upon request, we will provide a copy of your processed personal data without undue delay. For repeated or excessive requests, we may charge a reasonable fee to cover administrative costs. Access to your medical documentation held by a partner provider is exercised at that partner provider under the rules of Section 65 of Act No. 372/2011 Coll.

Right to Rectification

If you believe any of your personal data is inaccurate or incomplete, you have the right to request correction or completion without undue delay.

Right to Restriction of Processing

You may request restriction of processing in specific cases, for example when you contest the accuracy of your data, when processing is unlawful but you prefer restriction over deletion, when we no longer need the data but you need it for legal claims, or when you have objected to processing and verification is pending.

Right to Object

You may object to processing based on our legitimate interests or carried out in the public interest. If you object, we will only continue processing where we can demonstrate compelling legitimate grounds or where processing is necessary for the establishment, exercise, or defence of legal claims. If you object to direct marketing, we will stop immediately. For processing based on a legal obligation, this right does not apply.

Right to Erasure ("Right to Be Forgotten")

You have the right to have your personal data erased in certain cases, particularly when we no longer need it or when you have withdrawn consent and there is no other legal basis for processing. This right does not apply where processing remains necessary to comply with our legal obligations, for archiving in the public interest, scientific research, or for the establishment, exercise, or defence of legal claims.

Right to Data Portability

Where processing is based on consent or on a contract and is carried out by automated means, you have the right to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller.

Right to Lodge a Complaint

You have the right to lodge a complaint with the Office for Personal Data Protection (www.uoou.cz) at any time if you believe your data is being processed unlawfully.

Automated Decision-Making and AI

OpenMedical does not use automated decision-making producing legal or similarly significant effects on you without human involvement. AI-assisted tools used within OpenMedical are limited to support functions and are subject to human oversight, as described in the section on AI-assisted tools above. Clinical decisions are made by clinicians at partner providers and are not produced by any AI system used by OpenMedical.

Security Measures

  • Encryption of sensitive data in transit and at rest
  • Strict role-based access control separating clients, support, coordinators, and administrators
  • Logging and auditing of access to your account and uploaded documents, including downloads
  • Identity verification appropriate to the membership and coordination service
  • Separation of production and non-production environments
  • Regular staff training and confidentiality obligations
  • Vendor due diligence and written data processing agreements
  • Incident response and breach notification procedures

How to Exercise Your Rights

For any matter relating to the processing of your personal data, including enquiries, exercise of rights, complaints, or other suggestions, you can contact our privacy contact point.

We will handle your request without undue delay and in any case within one month of receipt. In exceptional cases, particularly due to the complexity or volume of requests, we may extend this period by a further two months. You will be informed of any such extension and the reasons for it.

  • Postal: Klinika Krejcárek s. r. o., Prosecká 876/89, Prosek, 190 00 Prague 9, Czech Republic
  • By e-mail at: privacy@openmedical.cz