Privacy Policy

Introduction

Ortho Reform respects your privacy and is committed to protecting your personal data. We have written this Privacy Policy in clear, plain language to explain how we collect, use, and safeguard your information when you use our website. Our clinic is based in Greece, and we comply with the European Union's General Data Protection Regulation (GDPR) and Greek data protection laws.

No Cookies or Trackers: This website does not use any cookies, tracking tools, analytics, or third-party scripts. The only personal data we collect is what you choose to give us via our contact form (for example, when booking an appointment).

Consent via Contact Form: Before you submit the contact form, we will ask you to check a box stating “I agree to the Privacy Policy.” (This checkbox provides a link to this Privacy Policy so you can read it first.) By ticking this box and submitting the form, you confirm that you have read and accepted how we will handle your data, as explained below.

Personal Data We Collect and Why

The only personal data we collect through our website is the information you provide when you fill out our appointment contact form. Specifically, we may ask for:

  • First Name and Last Name: So we know who you are and how to address you.
  • Email Address: To contact you with information or confirmation about your appointment request.
  • Phone Number: To call or text you if needed for scheduling or urgent communication about your inquiry.
  • Message: Any additional details you choose to provide about your appointment request or question.

We collect this information only so that we can respond to your inquiry, schedule the appointment you requested, or provide the information you need. Providing this data is voluntary, but if you don't provide the necessary contact details, we won't be able to get in touch with you or book the appointment.

Please do not include any sensitive personal or medical information in the message field. The contact form is intended for general inquiries and appointment requests only. For any detailed medical information or personal health issues, please speak directly with our medical staff in person or via a secure channel. This is to protect your privacy, since email is not intended for sharing confidential health details.

Lawful Basis for Processing

Under the GDPR, we must have a legal reason (lawful basis) to collect and use your personal data. For the contact form on our site, our lawful bases are:

  • Consent: By checking the “I agree to the Privacy Policy” box and submitting the form, you give us your consent to process (use) your information for the purposes described. This consent is clear and voluntary.
  • Legitimate Interest: We have a legitimate interest in responding to people who contact us for our services. If you request an appointment or information, it's in both your interest and ours to use your data to reply and assist you. This is another legal basis under GDPR for us to handle your data in the context of your inquiry.

We only use your data in ways you would expect when contacting a medical clinic. You have the right to withdraw your consent at any time (see Your Rights below), but note that if you do so, we will not be able to continue communication unless we have another lawful basis to rely on.

How We Use Your Data

We use the personal information you provide only for the following purposes:

  • To contact you in response to your inquiry or appointment request (for example, replying to your email or calling you if you provided a phone number).
  • To schedule, confirm, or manage an appointment that you asked for.
  • To provide information or answer questions you have asked about our medical services.

We do not use your data for any other purpose. We will never use your information for marketing, advertising, or newsletters, and we will not send you any unrelated communications you didn't ask for. We also never sell or share your personal information with marketers or other companies.

Additionally, we do not use your data for any kind of automated decision-making or profiling. Every decision or communication involving your data (such as confirming an appointment) is done by our human staff, not by algorithms.

How We Store and Protect Your Data

When you submit the contact form, your information is sent directly to our clinic's email inbox. We use a secure email service (a premium Gmail account through Google Workspace) to receive and manage these messages. This means your form submission is stored as an email in our Gmail inbox. Google Workspace is a professional service that meets European data privacy standards (GDPR-compliant) and it stores data securely on Google's servers.

We take appropriate measures to protect your personal data. Our website is encrypted using HTTPS, so the information you send through the form is transmitted securely. Our email systems are protected with strong passwords and security protocols. We also keep our devices and network secure to prevent unauthorized access to your information.

Only authorized clinic staff can access the contact form submissions in our email. This typically includes our front-desk staff responsible for scheduling and the medical professionals who will attend to your appointment. All staff members are bound by confidentiality agreements and the ethical duties of patient privacy. We treat your personal information with the same care as we treat medical records.

We do not share your personal data with any third parties. Your information stays within our clinic. The only external service involved is our email provider (Google), which simply stores and forwards the emails for us. Google does not access or use the content of our emails for any purpose other than delivering and storing them. Aside from that, we do not give anyone outside the clinic access to your details. We also do not use any third-party cloud databases or external tools to store your data — everything is contained in our secure email system.

How Long We Keep Your Data

We keep your personal data for only as long as necessary to fulfill the purposes we collected it for (responding to you and scheduling your appointment). We do not keep your information indefinitely.

For contact form inquiries, we will typically retain the email (with your name and contact details) for no longer than 12 months after our last interaction with you. Keeping the email for a short period helps us refer to our conversation if you contact us again or have a follow-up question within that time. After that period, we will delete the email and any personal data contained in it.

We may keep your information for a longer period only if it is necessary for an ongoing service you are using or if we are required by law to retain it. For example, if you end up scheduling an appointment and receiving treatment, we might need to retain certain information as part of our medical records obligations. In all cases, we will not keep data longer than needed.

You also have the right to ask us to delete your information at any time. If you request deletion (see Your Rights below), we will erase your personal data from our records (unless we are legally required to keep it for a certain time).

Your Rights Under GDPR

As a user of our website and as a data subject under the GDPR, you have several important rights regarding your personal data. We are committed to respecting these rights and making it easy for you to exercise them. Your rights include:

Right of Access

You have the right to ask us if we are processing any personal data about you, and to request a copy of that data. We will provide you with a summary of the information we have about you, if any, and explain why we have it.

Right to Rectification

If you believe any of the personal data we have is incorrect or incomplete (for example, a typo in your email or phone number), you have the right to request that we correct or update it. We will fix any inaccuracies promptly.

Right to Erasure (Deletion)

You can request that we delete the personal data we hold about you. If you withdraw your consent or if your data is no longer needed for the original purpose, you have the right to be forgotten. We will securely delete your information upon request, provided there is no legal obligation for us to keep it.

Right to Restrict Processing

You have the right to ask us to limit or pause the processing of your data in certain situations. For example, if you believe the data is inaccurate or you have objected to our use of your data, you can request a restriction. This means we would store your data but not use it until the issue is resolved.

Right to Data Portability

You have the right to obtain the personal data you provided to us in a structured, commonly used, machine-readable format (for example, a CSV text file). You can also ask us to transfer this data to another service provider if that's relevant. This right typically applies if we are processing your data based on your consent and the processing is carried out by automated means. In practical terms, since our interactions are through a simple contact form, if you needed this, we could, for instance, forward you the original email you sent us or compile the details you provided.

Right to Object

You have the right to object to our processing of your personal data if you feel it impacts your fundamental rights and freedoms. Given the limited way we use your data (only to respond to you upon your request), this is unlikely to be an issue. However, you can object, for example, to any further contact from us. If you object, we will stop processing your data for that purpose immediately unless we have a compelling legitimate reason to continue (which is rare).

Right to Withdraw Consent

If we are processing your data based on consent, you have the right to withdraw that consent at any time. For our contact form, this means you can tell us that you no longer want us to hold or use your information. Once you withdraw consent, we will stop processing your data and, as mentioned, delete it (unless we have another lawful basis to keep it). Withdrawing consent will not affect any use of your data that happened before you withdrew.

These rights are provided to you by law, and we are here to uphold them. There are some conditions and legal exceptions to these rights, but in general, we will do everything we can to accommodate your request. We will not discriminate against you for exercising any of these rights.

To exercise any of your rights, simply contact us using the information in the next section. We will respond to your request as soon as possible, and certainly within one month as required by the GDPR.

Contact Us

If you have any questions about this Privacy Policy or about how we handle your personal data, please feel free to contact us. We also encourage you to reach out if you want to exercise any of your privacy rights or if you have a concern about your data.

Contact Information for Ortho Reform:

Email: info@orthoreform.com
Phone: +30 210 7299448
Mobile: +30 694 082 4855
Address: Marasli 3, Kolonaki, Athens, Greece 10676

You can contact us through any of the methods above. Whether you prefer email, phone, or mail, we take privacy inquiries seriously. To help us process your request quickly, please mention that it's regarding privacy. For example, you can include a subject line like “Privacy Request” in your email, or inform our staff that your call is about a data privacy question. This will ensure we direct you to the right person (such as a privacy officer or clinic manager).

We will do our best to answer your questions and fulfill any requests regarding your personal data. As required by law, we will respond within 30 days at the latest, and usually much sooner.

Your Right to Lodge a Complaint:

We hope to resolve any privacy questions or concerns you have. However, if you believe we have not addressed your issue or you think we are violating your data protection rights, you have the right to file a complaint with the Hellenic Data Protection Authority (HDPA) - the national data protection regulator in Greece. You can contact the HDPA using the following details:

Address: 1-3 Kifissias Avenue, 115 23 Athens, Greece
Phone: +30 210 6475600
Email: contact@dpa.gr
Website: www.dpa.gr

The Hellenic DPA is the independent public authority responsible for enforcing data protection laws in Greece. If you have a concern about how your data is handled, you can report it to them. We would appreciate the chance to address your concerns first, but you are free to contact the DPA at any time.