How We Protect Your Data
Last updated: 13 August 2026
Your case may contain some of the most sensitive information there is — health data. This page explains, in plain language, how AIDA, operated by OTEXE Global Solutions OÜ (Registry Code 16536027, Vesivärava 50-201, 10152 Tallinn, Estonia), protects it. This page is a summary; the legally binding description of our processing is in our Privacy Policy.
Your data stays in the European Union
AIDA is hosted on infrastructure located in the EU region of our hosting provider. Your case materials — including photographs, imaging studies and treatment plans — are stored and processed within the European Union and protected under the GDPR, one of the strictest data protection frameworks in the world.
Your identity stays private until you decide otherwise
Clinics reviewing cases on AIDA see a de-identified version of your case: no name, no contact details. Your identity is revealed only to the clinic you choose, only when you request contact, and only after your explicit consent naming that clinic. Until that moment, no clinic knows who you are.
Everything runs on your consent
We process your health data only on the basis of your explicit consent (Article 9(2)(a) GDPR), collected step by step:
- consent to structure your case;
- consent to show the de-identified case to verified clinics;
- a separate consent, per clinic, before your identity is shared.
Each consent is optional, recorded, and can be withdrawn at any time in your account settings. Submitting your case is never a condition of browsing the Platform, and refusing any consent never results in worse treatment of your requests.
No tracking of health data — ever
We do not permit advertising or analytics technologies (cookies, pixels, web beacons) to operate in the areas of the Platform where your case materials are processed. Your health data is never used for advertising and is never sold. See our Cookie Policy.
Technical safeguards
- Encryption in transit (TLS) for all connections and encryption at rest for stored case materials;
- Access controls: case materials are accessible only to systems and personnel that strictly need them, under confidentiality obligations, with access logging;
- Segregation: health data is stored separately from marketing and analytics environments;
- Secure sharing: clinics receive your case only through access-controlled links, not as open attachments;
- AI under control: where AI features involve external model providers, they act under strict contracts, do not receive your data in identifiable form, and may not train their models on it;
- Retention limits: you can delete your case materials at any time; withdrawal of consent triggers deletion without undue delay, save for copies we must keep by law;
- Incident response: personal data breaches are handled under Articles 33–34 GDPR, including notification of the Estonian Data Protection Inspectorate within 72 hours and of affected users where required.
Your rights, always available
Access, rectification, erasure, restriction, objection, portability, withdrawal of consent, human review of AI outputs — all described in the Privacy Policy, all exercisable from your account or via support@aidadoc.com, answered within one month at the latest.
Independent oversight
We are supervised by the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee). You may complain to it, or to the data protection authority of your own EU country, at any time — no permission from us needed.
Questions about data protection: support@aidadoc.com.
