Privacy Policy

Privacy

Privacy Policy

How your personal data is handled when you visit this website, contact us or arrange an appointment.

Updated 2 September 2026DPhysio OÜ · registry code 16467390
Controller

DPhysio OÜ is responsible for the personal data described on this page. Questions and requests: [email protected].

What this site does

The site provides information and links for contact and booking. It has no user accounts, newsletter sign-up or online checkout.

Your choice

Necessary cookies support the site. Optional analytics should run only when you allow analytics cookies, and you can change that choice.

01

Controller and scope

The controller is DPhysio OÜ, an Estonian private limited company with registry code 16467390. You can contact us at [email protected], by phone at +372 5390 3489, or at our practice contact address: Tõnismägi 3a, 2nd floor, 10119 Tallinn, Estonia.

This policy covers this website, direct enquiries and private appointments arranged with us. If you follow a link to Calendly, WhatsApp, Google, Facebook, Instagram or Confido, that provider also processes data under its own privacy information.

02

Data we process

Website and security dataIP address, request time, browser and device information, pages viewed, referring page, security events and cookie preferences.
Enquiries and bookingsYour name, email address or phone number, preferred service and time, the content of your message, booking status and related correspondence.
Service informationInformation you choose to provide and details reasonably needed to assess, arrange and provide a session. This may include health information relevant to safe treatment.
Business recordsPayment, invoice and accounting information, and records needed to handle complaints or legal claims.

We receive data from you, from your browser or device, and—when you use them—from booking providers such as Calendly or Confido. We do not obtain marketing profiles from data brokers.

Please use care with sensitive information. Do not send unnecessary medical details through ordinary email or WhatsApp. For an emergency, call 112; do not use this website or its contact channels.
03

Why we use it

Operate and protect the siteOur legitimate interest in providing a reliable and secure website.
Answer questions and arrange a sessionSteps requested before a service contract and our legitimate interest in responding to you.
Provide and administer servicesPerformance of a contract and compliance with legal and professional obligations.
Process relevant health informationOnly where permitted by applicable law—for example, for health care by a professional bound by confidentiality or, where appropriate, with your explicit consent.
Measure website useYour consent for optional analytics cookies. Consent can be withdrawn at any time.
Keep required records and resolve disputesLegal obligations and our legitimate interest in establishing, exercising or defending legal claims.

We do not use your data for automated decisions that produce legal or similarly significant effects, and we do not sell personal data.

04

Cookies and external services

Cookies and Google Analytics

Necessary cookies remember consent choices and support security and basic functionality. The current consent settings are stored for approximately 11 months. Google Analytics 4 may collect usage data only when analytics cookies are enabled. You can accept, reject or later change optional categories through the site’s “Manage consent” control.

At the date shown above, the site does not use advertising pixels, social login or user accounts. Browser settings may also block cookies, although some essential functions may then work differently.

Booking and communication

The appointment button opens Calendly. Calendly processes booking data on our behalf and also explains its own controller activities in its privacy notice. WhatsApp is provided by Meta; its EEA privacy policy applies when you use that channel.

Other links

Google Maps, Facebook, Instagram and Confido are external services. Merely viewing this page does not open those services; if you follow a link, the destination receives the data normally sent by your browser and applies its own terms and privacy information. Google explains its practices in the Google Privacy Policy.

05

Sharing and international transfers

We disclose personal data only when needed to run the website, arrange or provide services, meet legal duties, or protect legitimate rights. Recipients may include hosting, security and technical-support providers; analytics and booking providers where enabled or used; payment and accounting providers; professional advisers; and public authorities where disclosure is required by law.

Some providers, including global technology and communication services, may process data outside the European Economic Area. Where we are responsible for such a transfer, we rely on a lawful mechanism such as an adequacy decision or approved standard contractual clauses and apply additional safeguards where required.

Confido manages bookings and patient information for services booked through its own channels under its own notices and conditions.

06

Retention and security

We keep data only for as long as needed for the purpose for which it was collected and for applicable legal, accounting, professional or claims periods. The exact period depends on the record:

  • ordinary enquiries are kept only while the matter is active and for a reasonable follow-up period;
  • booking and service records are kept for the period needed to provide the service and meet applicable professional or legal duties;
  • accounting source documents are generally retained for seven years under Estonian law;
  • cookie preferences are currently stored for approximately 11 months; analytics retention follows the configured service settings.

We use reasonable organisational and technical measures to restrict access, protect systems and reduce accidental loss, misuse or disclosure. No internet transmission or storage method is completely risk-free.

If an appointment concerns a child, a parent or legal guardian should provide the data and confirm that they are authorised to act for the child.

07

Your rights

Depending on the circumstances, you may ask for access to your data, correction, deletion, restriction, or a portable copy; object to processing based on legitimate interests; and withdraw consent without affecting earlier lawful processing. These rights are not absolute—for example, some records must be retained by law.

Send a request to [email protected]. We may ask for reasonable information to verify identity and will respond within the period required by law.

You may also complain to the Estonian Data Protection Inspectorate or to the supervisory authority where you live or work. We may update this policy when services, providers or legal requirements change; the current version and date will remain on this page.

Questions about your data?

Contact us to exercise a privacy right or ask how a particular booking or message is handled.