23 August 20261. Personal Data ControllerThis Privacy and Personal Data Processing Policy (the “Policy”) sets out the procedures and conditions governing the processing of personal data by
MEDTOUR GROUP S.R.L., operating under the commercial designation
MEDTOUR.MD (the “Controller”):
MEDTOUR GROUP S.R.L.IDNO: 1025600070021
Registered address: MD-2028, Republic of Moldova, Chișinău municipality, 11 Miorița Street, Apt. 45
Website: medtour.md (the “Website”)
E-mail: info@medtour.md
Telephone / Viber: +373 691 71 264
Other current communication channels of the Controller are indicated on the official Website.
The Controller provides organisational and coordination services in the field of medical tourism. Unless otherwise expressly provided by applicable law or the relevant agreement, the Controller is not a healthcare provider, does not provide medical care, does not make diagnoses and does not prescribe treatment.
2. Scope of ApplicationThis Policy applies to personal data received by the Controller:
- through the Website and its functionality;
- through contact and enquiry forms;
- by e-mail;
- by telephone;
- through Viber and other communication channels used by the Controller or indicated on the Website;
- during online and offline consultations;
- when receiving documents and medical information;
- when entering into and performing agreements;
- directly from the client;
- from the client’s legal or authorised representative;
- from healthcare organisations, physicians, diagnostic centres, laboratories and other participants involved in organising the service, where such data is obtained on a lawful basis.
3. Applicable LawAs of 23 August 2026, the Controller processes personal data in accordance with
Law of the Republic of Moldova No. 195/2024 on Personal Data Protection and other applicable legislation.
Where other mandatory legal provisions apply to a specific processing operation, the Controller complies with such provisions to the relevant extent.
4. Personal Data That May Be ProcessedDepending on the nature of the enquiry and the service requested, the Controller may process:
- identification data: first name, surname, date of birth, citizenship and information contained in identity documents, where necessary for a specific service;
- contact data: telephone number, e-mail address, country and city, username or another identifier used in the relevant communication service;
- the content of enquiries and business correspondence, including the date, time and communication channel used;
- travel and coordination information: dates, routes, bookings, accompanying persons, language and organisational preferences;
- contractual, payment and accounting information to the extent necessary;
- technical Website data and cookies, to the extent actually used and subject to applicable requirements and the user’s choices;
- health data and other special categories of personal data, only where necessary for the specific request and permitted by law.
The Controller applies the principle of data minimisation and asks individuals not to provide information that is not required for the relevant enquiry or service.
5. Health DataThe Controller may receive information concerning diagnoses and suspected diagnoses, complaints and medical history, medical records and extracts, laboratory and test results, medical opinions, prescriptions, information on previous treatment and surgical procedures, MRI/CT/X-ray/ultrasound and other medical images, photographs and other information concerning a person’s health that is provided for the purpose of arranging the requested service.
Health data constitute a special category of personal data. The Controller processes such data only where there is an appropriate legal basis and an additional condition applicable to special categories of personal data, as required by law.
Where the Controller relies on explicit consent as such a condition, that consent is requested separately before the relevant processing takes place. Submitting a standard enquiry, using the Website, continuing correspondence or consenting to marketing does not in itself constitute explicit consent to the processing of health data.
6. Purposes of ProcessingThe Controller may process personal data for the following purposes:
- receiving and handling enquiries;
- communicating with prospective and existing clients;
- determining the nature of the service requested;
- identifying an appropriate healthcare organisation or specialist;
- structuring medical information provided by the client;
- obtaining a preliminary assessment of a medical case, an examination or treatment programme, or a second medical opinion;
- obtaining indicative cost information;
- transmitting necessary medical information to a selected or prospective healthcare provider;
- arranging consultations, diagnostics, examinations, treatment and travel;
- arranging transfers, accommodation, translation and other agreed services;
- preparing, entering into and performing agreements;
- processing payments and maintaining accounting and tax records;
- providing ongoing client coordination and support;
- ensuring the security of information systems and preventing abuse;
- complying with legal obligations;
- establishing, exercising or defending legal claims;
- handling requests from data subjects;
- marketing communications, only where an appropriate legal basis exists.
7. Legal Bases for ProcessingDepending on the purpose and circumstances, the Controller may process personal data on the basis of:
- the consent of the data subject;
- the necessity to take steps at the request of the data subject prior to entering into a contract;
- entering into and performing a contract;
- compliance with a legal obligation to which the Controller is subject;
- the legitimate interests of the Controller or a third party, where and to the extent permitted by law;
- the establishment, exercise or defence of legal claims;
- other legal grounds provided for by applicable legislation.
The legitimate interests of the Controller may include ensuring the security of the Website and information systems, preventing abuse and fraud, maintaining necessary business records, improving the organisation of services and protecting the Controller’s rights in connection with complaints or legal proceedings, provided that the rights and freedoms of data subjects are respected.
For health data and other special categories of personal data, the relevant additional condition required by law also applies.
The Controller does not use consent as a universal legal basis for all processing operations.
8. Requirement to Provide Data and Consequences of Failure to Provide ItProviding personal data is voluntary in most cases. However, certain information may be objectively necessary to respond to an enquiry, prepare a proposal, enter into and perform an agreement, comply with a legal obligation or arrange a medical service.
If a data subject does not provide information without which the relevant request cannot be fulfilled, the Controller may be unable to review the medical case, obtain an offer from a healthcare provider, enter into an agreement or provide the relevant organisational and coordination service.
9. Sources and Channels Through Which Data Is ObtainedThe primary source of personal data is the data subject.
Data may also be received from a legal or authorised representative, an accompanying person, a healthcare organisation, physician, diagnostic centre, laboratory, translator or another service provider where this is necessary to fulfil the request and is permitted by law.
Personal data may be provided to the Controller through the Website, e-mail, telephone, Viber and other communication channels used by the Controller or indicated on the official Website.
A person providing the Controller with personal data relating to another adult must have an appropriate lawful basis or authority to do so.
10. Viber and Other Communication ChannelsViber and other electronic communication services used by the Controller may be used for initial enquiries, exchange of information, receipt of documents, coordination of services, recording electronic confirmations and informing clients about the progress of their request.
Such services may be provided by independent service providers. When they are used, certain information may technically be processed by such providers in accordance with their own terms and privacy policies, including through infrastructure located outside the Republic of Moldova.
The Controller limits the volume of data exchanged in accordance with the principle of necessity and applies measures appropriate to the level of risk. Where a significant volume of medical or other sensitive information is involved, the Controller may recommend another managed method of transmission.
Electronic communication services are not used by the Controller as a permanent medical archive.
11. Recipients of Personal DataTo the extent necessary for a specific purpose, personal data may be disclosed to:
- healthcare organisations;
- physicians and other healthcare professionals;
- diagnostic centres and laboratories;
- translators and translation agencies;
- transfer and accommodation service providers;
- IT, hosting, cloud and communication service providers;
- banks and payment service providers;
- accounting service providers;
- legal and other professional advisers;
- public authorities and institutions where required by law;
- other parties whose involvement is necessary to arrange the agreed service.
Access to or disclosure of data is limited to what is necessary for the relevant task.
The Controller does not sell clients’ personal or medical data.
A healthcare organisation that independently determines the purposes and means of diagnosis, treatment and maintenance of medical records will generally act as an independent controller in relation to its own processing activities.
12. Transfers to Healthcare OrganisationsThe Controller may disclose the necessary amount of medical information to selected or prospective healthcare organisations and specialists for the purpose of preliminary case assessment, determining whether consultation, examination or treatment is possible, obtaining a medical opinion or second opinion, preparing a proposed programme and indicative cost estimate, and arranging a consultation or hospital admission.
The Controller applies the principle of data minimisation and does not disclose information that is not objectively required for the specific purpose.
Once the healthcare organisation and destination country have been determined, the Controller records the relevant recipient and transfer in its internal documentation.
13. International TransfersBecause the Controller arranges medical and related services in different countries and uses international information and communication service providers, personal data may be transferred to or become accessible from outside the Republic of Moldova.
Transfers to countries within the
European Economic Area (EEA) are carried out subject to the free movement of personal data regime provided for by applicable law and do not require special authorisation solely because the recipient is located in the EEA.
For other countries, before making a transfer, the Controller determines the applicable mechanism under Law No. 195/2024, including, depending on the circumstances, an adequacy decision, appropriate safeguards, standard contractual clauses or a statutory derogation applicable to the specific situation.
Where a specific international transfer to a country without an adequacy decision and without appropriate safeguards is made on the basis of the data subject’s explicit consent as a statutory derogation, before obtaining such consent the Controller separately informs the data subject about the relevant country and/or recipient and the possible risks associated with the transfer.
Explicit consent to the processing of health data does not in itself replace any international transfer mechanism that may be required by law.
14. IT, Cloud and Communication Service ProvidersFor operation of the Website, corporate e-mail, document storage, communications, backups, analytics and other organisational purposes, the Controller may use external service providers.
When selecting service providers, the Controller takes into account the nature of the data, the level of risk, contractual terms, geographical location of processing and available safeguards.
The Controller maintains an internal register of service providers and international data transfers.
15. Retention PeriodsThe Controller does not retain personal data for longer than necessary for the purposes for which it was obtained, unless longer retention is required or permitted by law.
When determining retention periods, the Controller takes into account the nature and status of the enquiry, the period during which services are provided, contractual relationships, mandatory accounting and tax retention periods, limitation periods, the need to handle complaints and defend legal claims, and technical backup cycles.
Medical files are kept separate from accounting and corporate archives and are deleted once medical coordination has been completed and there is no lawful need for their further retention, in accordance with the Controller’s internal Retention and Deletion Policy.
Upon request, the Controller provides the data subject with information about the applicable retention period or the criteria used to determine it.
16. Personal Data SecurityThe Controller implements technical and organisational measures appropriate to the nature of the data and the associated risks, including access restrictions based on the need-to-know principle, individual user accounts, multi-factor authentication where available, protection of work devices, management of access to cloud resources, control of external access, backup and recovery procedures, revocation of access following termination of authority, confidentiality obligations and incident response procedures.
The Controller regularly reviews its security measures taking into account relevant risks and technologies used.
17. Security Incidents and Personal Data BreachesThe Controller documents identified personal data security breaches, takes measures to limit their consequences and assesses the risks to the rights and freedoms of data subjects.
Where applicable law requires notification to the
National Center for Personal Data Protection of the Republic of Moldova and/or affected data subjects, the Controller provides such notification in accordance with the applicable procedure and time limits.
18. Rights of the Data SubjectIn the cases and to the extent provided by law, a data subject has the right to:
- obtain information concerning the processing of their personal data and access such data;
- obtain a copy of the personal data being processed;
- request correction of inaccurate or incomplete data;
- request erasure of personal data;
- request restriction of processing;
- object to processing;
- object to direct marketing;
- exercise the right to data portability, where applicable;
- withdraw previously given consent;
- obtain information concerning recipients of personal data where required by law;
- not be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them, where the relevant right applies;
- lodge a complaint with the National Center for Personal Data Protection of the Republic of Moldova;
- apply to a court or use other remedies provided by law.
Withdrawal of consent applies prospectively and does not affect the lawfulness of processing carried out before consent was withdrawn. Withdrawal of consent also does not require deletion of data that the Controller is required or entitled to continue processing on another lawful basis.
19. How to Contact the ControllerA request may be submitted:
- by e-mail to: info@medtour.md;
- by telephone / Viber: +373 691 71 264;
- to the Controller’s registered address;
- by another official communication method indicated by the Controller.
The request should preferably include the individual’s first and last name, contact details, the substance of the request, information enabling the relevant enquiry or case to be identified and the preferred method of receiving a response.
For data protection purposes, the Controller may request information that is objectively necessary to verify the identity of the applicant.
Requests are handled without undue delay and within the time limits established by applicable law.
20. Marketing CommunicationsMarketing communications are sent only where an appropriate legal basis exists. Where consent is relied upon, it is requested separately and is not a condition for submitting an initial enquiry, having a medical case reviewed, entering into an agreement or receiving the Controller’s primary services.
A data subject may opt out of marketing communications at any time. Such opt-out does not terminate service-related communications necessary to fulfil an ongoing request or agreement.
21. Cookies and Third-Party ServicesThe use of cookies and similar technologies is governed by the Website’s separate Cookie Policy and the actual settings of the Website.
The Website may contain links, widgets or integrations provided by independent third-party services. After accessing an external resource, personal data may be processed by the relevant provider in accordance with its own privacy policy.
The Controller does not determine the purposes and means of independent processing carried out by such third-party provider, except where the provider acts on behalf of the Controller.
22. MinorsWhere a service is arranged for a minor, the Controller processes the minor’s personal data to the extent necessary and communicates with the parent, legal representative or another person having the authority required by law.
The Controller may request evidence of such authority.
23. Automated Decision-MakingAs a general rule, the Controller does not make decisions that produce legal or similarly significant effects for a client solely on the basis of fully automated processing.
If such processing is introduced, the data subject will be provided with the information and safeguards required by law.
24. Relationship with Other DocumentsThis Policy governs the processing of personal data and constitutes a separate public document.
The rules governing use of the Website, the role of the Controller and the general terms applicable to use of its functionality are set out in the Terms of Use published on the Website.
Where the Controller relies on explicit consent for the processing of health data, such consent is obtained through a separate document or an unambiguous electronic action taken by the data subject after the relevant information has been provided.
Acceptance of the Terms of Use does not constitute consent to the processing of health data. This Policy does not replace separate explicit consent where such consent is required.
Consent to marketing is obtained separately from consent or other arrangements relating to medical coordination.
25. Amendments to the PolicyThe Controller may amend this Policy where there are changes to applicable legislation, services, purposes or methods of processing, systems used, service providers, destination countries for data transfers or communication channels.
The current version is published on the Website together with the date of its latest update.
Where an amendment materially affects the conditions governing processing, the Controller takes appropriate measures to provide additional information to data subjects and, where required, obtains new consent.
26. Final ProvisionsThe mere fact of visiting or continuing to use the Website does not constitute consent to all possible types of personal data processing.
Where applicable law requires consent, the Controller obtains it through a separate affirmative action by the data subject.
For questions concerning the processing and protection of personal data:MEDTOUR GROUP S.R.L.IDNO: 1025600070021
Registered address: MD-2028, Republic of Moldova, Chișinău municipality, 11 Miorița Street, Apt. 45
E-mail: info@medtour.md
Telephone / Viber: +373 691 71 264
Website: medtour.md