Privacy policy

Template. Have a lawyer review this text before the site goes live.

Updated: [date]

We handle your personal data, especially health information, responsibly and only as far as needed to provide our service. We follow the General Data Protection Regulation (EU) 2016/679 (GDPR) and Lithuanian law. This page explains what we collect, why, how long we keep it and what rights you have.

1. General

1.1. Data controller: [Įmonės pavadinimas] ("KINERA", "we"), company code [Įmonės kodas], address [Registracijos adresas], email [el. paštas], phone [telefono numeris].

1.2. Personal data means any information that can identify you directly or indirectly, such as your name, email or phone number.

1.3. This policy applies when you visit the site, book a consultation, order a plan, fill in the questionnaire or contact us in any other way.

1.4. We may update this policy. The latest version is always published on this page, with the update date shown at the top.

2. How we get your data

You are responsible for the accuracy of the data you provide. If you provide someone else's data (e.g. your child's), you must be entitled to do so on their behalf.

  • When you give it to us: signing up, filling in the questionnaire or contact form, emailing us.
  • When it arises from the service: notes about your condition taken during the consultation and the exercise plan we create.
  • From providers that help us work: for example, Stripe tells us a payment was received.

3. Why we process data and what data

Providing consultations and plans

Data processed
Name, email, phone, health information (injuries, pain, surgeries, activity level), training goals, consultation notes, the plan created.
Retention period
For the duration of the service and [10] years after the last service, unless you withdraw consent earlier.
Legal basis
Performance of a contract (GDPR Art. 6(1)(b)); for health data, your explicit consent (GDPR Art. 9(2)(a)).

Bookings and reminders

Data processed
Name, email, chosen service, physiotherapist, date and time, video call link.
Retention period
Until the service is provided and [1] year after.
Legal basis
Entering into and performing a contract (GDPR Art. 6(1)(b)).

Payments and accounting

Data processed
Name, email, service, amount, payment date and status. We never receive card details; Stripe handles them.
Retention period
As required by accounting law (usually 10 years).
Legal basis
Legal obligation (GDPR Art. 6(1)(c)); performance of a contract (GDPR Art. 6(1)(b)).

Handling questions, requests and complaints

Data processed
Name, email, content of the message and reply.
Retention period
For the duration of the correspondence and [1] year after; in a dispute, until it is resolved and [3] years after.
Legal basis
Your consent (GDPR Art. 6(1)(a)); legitimate interest in replying and defending our rights (GDPR Art. 6(1)(f)).

Site operation and security

Data processed
IP address, browser type, request times (server logs).
Retention period
As set by the hosting provider, but no longer than [30] days.
Legal basis
Legitimate interest in keeping the site secure (GDPR Art. 6(1)(f)).

Where we rely on your consent, you can withdraw it at any time. Withdrawal doesn't affect processing carried out before it.

4. Our principles

  • We collect only the data needed for the stated purposes.
  • We process it lawfully, fairly and transparently.
  • We promptly correct or delete inaccurate data.
  • We don't keep data longer than necessary.
  • We never sell your data or share it except as described in this policy.

5. Who we share data with

5.1. We share data only with service providers (processors) that help us work, and only as far as they need it:

  • Stripe Payments Europe Ltd. (Ireland): payment processing.
  • Cal.com, Inc. (USA): booking, calendar and video call links.
  • Resend (Plus Five Five, Inc., USA): sending email.
  • [Hosting provider, e.g. Vercel Inc. (USA)]: website hosting.
  • [Accounting provider]: accounting.

5.2. Where the law requires, we may provide data to public authorities such as the State Tax Inspectorate, courts or law enforcement.

5.3. Some providers are outside the European Economic Area (EEA). In that case data is transferred only under GDPR safeguards: the European Commission's standard contractual clauses or the EU-US Data Privacy Framework.

6. Your rights

6.1. Send requests to [el. paštas]. We may ask you to confirm your identity.

6.2. We'll reply within 1 month. For complex requests we may extend this by 2 more months and will tell you so within the first month.

6.3. After erasure we may keep only what the law requires (e.g. accounting records) or what is needed to resolve a dispute.

  • To know how your data is processed.
  • To access your data and get a copy.
  • To have inaccurate data corrected or incomplete data completed.
  • To have your data erased (the "right to be forgotten") when it is no longer needed, you withdraw consent, or it is processed unlawfully.
  • To restrict processing while we look into your request.
  • To receive your data in a common machine-readable format and move it to another controller.
  • To object to processing based on legitimate interest.
  • To withdraw consent at any time.
  • To complain to the State Data Protection Inspectorate (vdai.lrv.lt). We'd encourage you to contact us first; we'll try to resolve things quickly.

7. How we protect data

7.1. We use technical and organisational measures: encrypted connections (HTTPS), access limited to the physiotherapists who need the data, strong passwords and two-factor authentication on provider accounts.

7.2. Our physiotherapists are bound not to disclose your data to third parties.

8. Cookies

How we use cookies is described on the Cookies page.