Our Commitment to GDPR Compliance
At DocAI Health, we are committed to protecting the privacy and personal data of individuals located in the European Economic Area (EEA), the United Kingdom, and Switzerland.
We respect your rights under the General Data Protection Regulation ("GDPR") and are committed to handling personal information lawfully, fairly, transparently, and securely.
This page explains how we process personal data and how users can exercise their rights under applicable data protection laws.
1 Who We Are
DocAI Health is an AI-powered health guidance platform that provides informational health support and wellness-related services through artificial intelligence technologies.
For the purposes of the GDPR, DocAI Health acts as a data controller for the personal information collected through our platform.
For privacy-related inquiries, please contact:
2 Personal Data We Collect
Depending on how you use our Services, we may collect:
Account Information
- Full name
- Email address
- Date of birth
- Language preferences
Health Information
- Symptoms submitted by users
- Health-related information voluntarily provided
- Medication information
- Consultation history
- User interactions with AI systems
Technical Information
- IP address
- Device information
- Browser information
- Usage data
- Security logs
3 Legal Bases for Processing
Under GDPR, we process personal data based on one or more of the following legal grounds:
Consent
Where you voluntarily provide information and consent to its processing.
Contractual Necessity
To provide access to the Services you request.
Legitimate Interests
To improve services, maintain security, prevent fraud, and operate our platform.
Legal Obligations
Where processing is required by applicable laws or regulations.
4 Special Category Health Data
Health-related information is considered a special category of personal data under GDPR.
DocAI Health processes health-related information only when:
- You voluntarily provide such information.
- You explicitly consent to the processing.
- Processing is necessary to provide requested Services.
We apply additional safeguards to protect health-related information.
5 Your GDPR Rights
If you are located within the EEA, UK, or Switzerland, you may have the following rights:
Right of Access
You may request access to the personal information we hold about you.
Right to Rectification
You may request correction of inaccurate or incomplete information.
Right to Erasure
You may request deletion of your personal data under certain circumstances.
Right to Restrict Processing
You may request limitations on how your information is processed.
Right to Object
You may object to certain types of data processing.
Right to Data Portability
You may request a copy of your information in a structured and machine-readable format.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw your consent at any time.
6 Exercising Your Rights
To exercise any GDPR rights, contact us at:
We may request identity verification before processing requests.
We will respond within applicable legal timeframes.
7 Automated Decision-Making
DocAI Health utilizes artificial intelligence systems to generate health guidance and recommendations.
Users acknowledge that:
- AI-generated responses are automated.
- AI-generated content is informational only.
- AI outputs do not constitute professional medical advice.
Users have the right to request additional information regarding automated processing where applicable.
8 Data Retention
We retain personal information only for as long as necessary to:
- Provide Services
- Maintain account functionality
- Comply with legal obligations
- Resolve disputes
- Enforce agreements
When data is no longer needed, it is securely deleted or anonymized.
9 International Data Transfers
Because DocAI Health operates globally, personal information may be processed outside the European Economic Area.
Where international transfers occur, we implement appropriate safeguards, including:
- Standard Contractual Clauses (SCCs)
- Secure cloud infrastructure
- Contractual privacy protections
These measures are designed to ensure adequate protection of personal data.
10 Data Security
We implement technical and organizational measures designed to protect personal information, including:
- Encryption in transit
- Secure storage systems
- Access controls
- Security monitoring
- Incident response procedures
While no system is completely secure, we continuously improve our security practices.
11 Complaints
If you believe your personal information has been processed in violation of GDPR, you have the right to lodge a complaint with your local Data Protection Authority.
We encourage users to contact us first so we can attempt to resolve concerns promptly.
12 Updates to This Notice
We may update this GDPR Compliance Notice from time to time.
Any changes will be posted on this page with an updated revision date.
Continued use of the Services after updates constitutes acceptance of the revised notice.
13 Contattaci
For GDPR-related inquiries:
Our Commitment
DocAI Health is committed to respecting your privacy, protecting your personal information, and maintaining compliance with international data protection standards.
We believe that trust, transparency, and responsible data practices are essential components of modern digital healthcare.