Privacy policy
Template. Have a lawyer review this text before the site goes live.
Updated: [date]
We handle your personal data, especially health information, responsibly and only as far as needed to provide our service. We follow the General Data Protection Regulation (EU) 2016/679 (GDPR) and Lithuanian law. This page explains what we collect, why, how long we keep it and what rights you have.
1. General
1.1. Data controller: [Įmonės pavadinimas] ("KINERA", "we"), company code [Įmonės kodas], address [Registracijos adresas], email [el. paštas], phone [telefono numeris].
1.2. Personal data means any information that can identify you directly or indirectly, such as your name, email or phone number.
1.3. This policy applies when you visit the site, book a consultation, order a plan, fill in the questionnaire or contact us in any other way.
1.4. We may update this policy. The latest version is always published on this page, with the update date shown at the top.
2. How we get your data
You are responsible for the accuracy of the data you provide. If you provide someone else's data (e.g. your child's), you must be entitled to do so on their behalf.
- When you give it to us: signing up, filling in the questionnaire or contact form, emailing us.
- When it arises from the service: notes about your condition taken during the consultation and the exercise plan we create.
- From providers that help us work: for example, Stripe tells us a payment was received.
3. Why we process data and what data
Providing consultations and plans
- Data processed
- Name, email, phone, health information (injuries, pain, surgeries, activity level), training goals, consultation notes, the plan created.
- Retention period
- For the duration of the service and [10] years after the last service, unless you withdraw consent earlier.
- Legal basis
- Performance of a contract (GDPR Art. 6(1)(b)); for health data, your explicit consent (GDPR Art. 9(2)(a)).
Bookings and reminders
- Data processed
- Name, email, chosen service, physiotherapist, date and time, video call link.
- Retention period
- Until the service is provided and [1] year after.
- Legal basis
- Entering into and performing a contract (GDPR Art. 6(1)(b)).
Payments and accounting
- Data processed
- Name, email, service, amount, payment date and status. We never receive card details; Stripe handles them.
- Retention period
- As required by accounting law (usually 10 years).
- Legal basis
- Legal obligation (GDPR Art. 6(1)(c)); performance of a contract (GDPR Art. 6(1)(b)).
Handling questions, requests and complaints
- Data processed
- Name, email, content of the message and reply.
- Retention period
- For the duration of the correspondence and [1] year after; in a dispute, until it is resolved and [3] years after.
- Legal basis
- Your consent (GDPR Art. 6(1)(a)); legitimate interest in replying and defending our rights (GDPR Art. 6(1)(f)).
Site operation and security
- Data processed
- IP address, browser type, request times (server logs).
- Retention period
- As set by the hosting provider, but no longer than [30] days.
- Legal basis
- Legitimate interest in keeping the site secure (GDPR Art. 6(1)(f)).
Where we rely on your consent, you can withdraw it at any time. Withdrawal doesn't affect processing carried out before it.
4. Our principles
- We collect only the data needed for the stated purposes.
- We process it lawfully, fairly and transparently.
- We promptly correct or delete inaccurate data.
- We don't keep data longer than necessary.
- We never sell your data or share it except as described in this policy.
5. Who we share data with
5.1. We share data only with service providers (processors) that help us work, and only as far as they need it:
- Stripe Payments Europe Ltd. (Ireland): payment processing.
- Cal.com, Inc. (USA): booking, calendar and video call links.
- Resend (Plus Five Five, Inc., USA): sending email.
- [Hosting provider, e.g. Vercel Inc. (USA)]: website hosting.
- [Accounting provider]: accounting.
5.2. Where the law requires, we may provide data to public authorities such as the State Tax Inspectorate, courts or law enforcement.
5.3. Some providers are outside the European Economic Area (EEA). In that case data is transferred only under GDPR safeguards: the European Commission's standard contractual clauses or the EU-US Data Privacy Framework.
6. Your rights
6.1. Send requests to [el. paštas]. We may ask you to confirm your identity.
6.2. We'll reply within 1 month. For complex requests we may extend this by 2 more months and will tell you so within the first month.
6.3. After erasure we may keep only what the law requires (e.g. accounting records) or what is needed to resolve a dispute.
- To know how your data is processed.
- To access your data and get a copy.
- To have inaccurate data corrected or incomplete data completed.
- To have your data erased (the "right to be forgotten") when it is no longer needed, you withdraw consent, or it is processed unlawfully.
- To restrict processing while we look into your request.
- To receive your data in a common machine-readable format and move it to another controller.
- To object to processing based on legitimate interest.
- To withdraw consent at any time.
- To complain to the State Data Protection Inspectorate (vdai.lrv.lt). We'd encourage you to contact us first; we'll try to resolve things quickly.
7. How we protect data
7.1. We use technical and organisational measures: encrypted connections (HTTPS), access limited to the physiotherapists who need the data, strong passwords and two-factor authentication on provider accounts.
7.2. Our physiotherapists are bound not to disclose your data to third parties.
8. Cookies
How we use cookies is described on the Cookies page.