Controller and scope
The controller is DPhysio OÜ, an Estonian private limited company with registry code 16467390. You can contact us at [email protected], by phone at +372 5390 3489, or at our practice contact address: Tõnismägi 3a, 2nd floor, 10119 Tallinn, Estonia.
This policy covers this website, direct enquiries and private appointments arranged with us. If you follow a link to Calendly, WhatsApp, Google, Facebook, Instagram or Confido, that provider also processes data under its own privacy information.
Data we process
We receive data from you, from your browser or device, and—when you use them—from booking providers such as Calendly or Confido. We do not obtain marketing profiles from data brokers.
Why we use it
We do not use your data for automated decisions that produce legal or similarly significant effects, and we do not sell personal data.
Cookies and external services
Cookies and Google Analytics
Necessary cookies remember consent choices and support security and basic functionality. The current consent settings are stored for approximately 11 months. Google Analytics 4 may collect usage data only when analytics cookies are enabled. You can accept, reject or later change optional categories through the site’s “Manage consent” control.
At the date shown above, the site does not use advertising pixels, social login or user accounts. Browser settings may also block cookies, although some essential functions may then work differently.
Booking and communication
The appointment button opens Calendly. Calendly processes booking data on our behalf and also explains its own controller activities in its privacy notice. WhatsApp is provided by Meta; its EEA privacy policy applies when you use that channel.
Other links
Google Maps, Facebook, Instagram and Confido are external services. Merely viewing this page does not open those services; if you follow a link, the destination receives the data normally sent by your browser and applies its own terms and privacy information. Google explains its practices in the Google Privacy Policy.
Sharing and international transfers
We disclose personal data only when needed to run the website, arrange or provide services, meet legal duties, or protect legitimate rights. Recipients may include hosting, security and technical-support providers; analytics and booking providers where enabled or used; payment and accounting providers; professional advisers; and public authorities where disclosure is required by law.
Some providers, including global technology and communication services, may process data outside the European Economic Area. Where we are responsible for such a transfer, we rely on a lawful mechanism such as an adequacy decision or approved standard contractual clauses and apply additional safeguards where required.
Confido manages bookings and patient information for services booked through its own channels under its own notices and conditions.
Retention and security
We keep data only for as long as needed for the purpose for which it was collected and for applicable legal, accounting, professional or claims periods. The exact period depends on the record:
- ordinary enquiries are kept only while the matter is active and for a reasonable follow-up period;
- booking and service records are kept for the period needed to provide the service and meet applicable professional or legal duties;
- accounting source documents are generally retained for seven years under Estonian law;
- cookie preferences are currently stored for approximately 11 months; analytics retention follows the configured service settings.
We use reasonable organisational and technical measures to restrict access, protect systems and reduce accidental loss, misuse or disclosure. No internet transmission or storage method is completely risk-free.
If an appointment concerns a child, a parent or legal guardian should provide the data and confirm that they are authorised to act for the child.
Your rights
Depending on the circumstances, you may ask for access to your data, correction, deletion, restriction, or a portable copy; object to processing based on legitimate interests; and withdraw consent without affecting earlier lawful processing. These rights are not absolute—for example, some records must be retained by law.
Send a request to [email protected]. We may ask for reasonable information to verify identity and will respond within the period required by law.
You may also complain to the Estonian Data Protection Inspectorate or to the supervisory authority where you live or work. We may update this policy when services, providers or legal requirements change; the current version and date will remain on this page.