Privacy Policy
Last updated: 11 August 2026
Your privacy matters to us. This Privacy Policy explains how OTEXE Global Solutions OÜ, Registry Code 16536027, VAT No. EE102515833, Vesivärava 50-201, 10152 Tallinn, Estonia (“OTEXE”, “we”) processes your personal data when you use aidadoc.com and the AIDA platform (the “Platform”). We have written it in plain language so that you can make informed decisions about your data.
Contact for all privacy matters: support@aidadoc.com.
1. Who is responsible for your data
OTEXE is the data controller of the personal data described in this Policy, except as set out below.
Clinics as independent controllers. When you choose a clinic and request an appointment or contact, and your case and identity are shared with that clinic, the clinic becomes an independent data controller of the data it receives. From that point, the clinic decides how it uses your data for its own professional purposes (for example, creating its own records, contacting you, preparing a treatment plan), under its own privacy policy and the healthcare record-keeping laws applicable to it. For questions or requests concerning a clinic’s use of your data, please contact that clinic directly; we will assist where we can.
2. What data we collect
- Account data: name, email address, telephone number, login credentials, country, language, consents and preferences.
- Case materials (only if you choose to submit them): photographs, radiological imagery such as CT/CBCT archives, existing treatment plans, case descriptions and related documents. These constitute data concerning health, a special category of personal data under Article 9 GDPR.
- Communications: messages you exchange with us or, through the Platform, with clinics; support requests.
- Technical and usage data: IP address, device and browser information, log data, session information, cookie identifiers (see our Cookie Policy).
We collect data directly from you, automatically when you use the Platform, and — where you request it — from clinics you interact with.
3. Why we process your data and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and managing your account; providing the Platform | Account, technical | Contract (Art. 6(1)(b) GDPR) |
| Structuring your case with AI assistance | Case materials | Your explicit consent (Art. 6(1)(a), Art. 9(2)(a) GDPR) |
| Making a de-identified version of your case available to verified clinics | De-identified case | Your explicit consent (Art. 9(2)(a) GDPR) |
| Revealing your identity and case to a clinic you choose and connecting you with it | Account, case materials | Your explicit consent (Art. 9(2)(a) GDPR), given per clinic |
| Service communications (confirmations, security notices) | Account | Contract |
| Marketing communications | Account | Consent (Art. 6(1)(a)); you can opt out at any time |
| Security, fraud prevention, abuse detection | Technical | Legitimate interest (Art. 6(1)(f)); legal obligation |
| Analytics and service improvement (non-health data) | Technical, usage | Legitimate interest; consent for non-essential cookies |
| Improvement of our services and AI features using de-identified or anonymised data derived from case materials | De-identified case data | Your explicit consent (Art. 9(2)(a) GDPR) — requested separately and never a condition of using the Platform |
| Handling complaints, legal claims, regulatory obligations | As relevant | Legal obligation; legitimate interest in defending claims |
Consent principles. Consent to the processing of your health data is requested separately for each distinct purpose, by a clear affirmative action (unticked checkboxes). It is entirely voluntary and is not a condition of browsing the Platform. You may withdraw any consent at any time in your account settings or via support@aidadoc.com, with effect for the future; withdrawal disables the corresponding features but does not affect processing already carried out. We do not use health data for advertising, and we do not sell personal data.
4. How our AI works
Our AI organises the materials you upload into a structured case file (for example, grouping images, extracting descriptive parameters you have provided, and preparing a de-identified summary for clinics). What it does not do: it does not make a diagnosis, does not recommend treatment, and does not make automated decisions producing legal or similarly significant effects concerning you within the meaning of Article 22 GDPR. Clinic proposals are prepared by the clinics themselves. You may at any time request human review of any AI-generated output, express your point of view and contest the output, by writing to support@aidadoc.com.
Where our AI features involve external model providers, such providers act as our processors under strict contractual and technical controls, do not receive your data in identifiable form, and may not use it to train or improve their own models.
5. Who receives your data
- Verified clinics — first only in de-identified form, and in identifiable form only for the clinic you choose (see Section 1);
- Service providers (processors) — cloud hosting, communications, customer support, IT security, analytics and payment providers, acting on our documented instructions; a current list of sub-processors is available on request at support@aidadoc.com;
- Professional advisers, auditors, lawyers — where necessary;
- Public authorities — where required by law or a lawful order;
- A successor entity — in the event of a merger, acquisition or reorganisation, under equivalent safeguards.
6. International transfers
The Platform is hosted on infrastructure located in the European Union (EU region of our hosting provider, Railway). Case materials, including health data, are stored and processed within the EU. Where data is transferred outside the EEA:
- to clinics located outside the EEA (for example, where you choose a clinic in a third country): the transfer takes place at your request and with your explicit consent after you have been informed that the destination country may not provide an equivalent level of data protection (Art. 49(1)(a) GDPR), and, where we have a data transfer agreement with the clinic, additionally under the European Commission’s Standard Contractual Clauses;
- to service providers in third countries (e.g., the United States): under the Standard Contractual Clauses and/or the EU–U.S. Data Privacy Framework, where applicable, with supplementary measures where needed.
You may request further information about transfer safeguards at support@aidadoc.com.
7. How long we keep your data
| Data | Retention |
|---|---|
| Account data | Life of the account + 3 years |
| Case materials (health data) | Until you delete them or withdraw consent; otherwise life of the account. Deleted without undue delay upon withdrawal, save for copies we must keep by law or to defend legal claims |
| Consents and consent logs | Life of the account + 3 years (to demonstrate compliance) |
| Communications and support tickets | 3 years from closure |
| Technical logs, security data | Up to 1 year; security incidents up to 6 years |
| Invoicing and accounting records | 7 years (Estonian Accounting Act) |
Inactive accounts: if you do not log in for 3 years, we will notify you and, absent a response, delete the account. When data is no longer needed, it is securely deleted or irreversibly anonymised.
8. Your rights
You have the right to: access your data; rectify inaccurate data; erase your data; restrict processing; object to processing based on legitimate interest; data portability; withdraw consent at any time; and not to be subject to solely automated decisions with legal or similarly significant effects. You may exercise these rights through your account self-service tools or by writing to support@aidadoc.com. We respond without undue delay and at the latest within one month; we may request information to verify your identity.
You also have the right to lodge a complaint with a supervisory authority: the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, Estonia, info@aki.ee, www.aki.ee) or the data protection authority of your EU country of residence.
9. Security
We apply appropriate technical and organisational measures, including encryption in transit and at rest, access controls, logging, segregation of health data, and staff confidentiality obligations. No system is absolutely secure; we notify affected users and authorities of personal data breaches as required by Articles 33–34 GDPR.
10. Children
The Platform is intended for persons aged 18 or over. We do not knowingly process children’s data. A parent or legal guardian may submit a dependant’s case only where legally authorised to do so and by confirming that authority.
11. Additional information for users in the United States
If you reside in a U.S. state with a consumer health data or comprehensive privacy law (for example, the Washington My Health My Data Act or the California Consumer Privacy Act), the following applies in addition: we collect and share consumer health data only with your consent as described in this Policy; we do not sell consumer health data and do not process it for targeted advertising; you have the rights of access, deletion and withdrawal of consent described above, and the right not to be discriminated against for exercising them. Requests: support@aidadoc.com. If your request is denied, you may appeal by replying to our decision; appeal outcomes will be explained in writing.
12. Changes to this Policy
We may update this Policy to reflect changes in our practices, technology or legal requirements. Material changes will be notified on the Platform and the “Last updated” date revised. Where a change concerns processing based on consent, we will seek fresh consent.
13. Contact
OTEXE Global Solutions OÜ · Registry Code 16536027 · Vesivärava 50-201, 10152 Tallinn, Estonia
Email: support@aidadoc.com
