Privacy Policy

Last updated: July 2026

1. Who we are & our two roles

Clinika OS is operated by Lopes2Tech, a sole proprietorship of Paulo Lopes, Riemenstrasse 1a, 8803 RΓΌschlikon, Switzerland ("we"). Our data-protection role depends on the data:

For clinic account, user and billing data we act as controller. For the patient and clinical data a clinic enters into the platform (appointments, contact details, clinical notes, intake, consent, treatment plans) the clinic is the controller and we act only as a processor, processing it solely on the clinic's documented instructions under our Data Processing Agreement (see below).

Contact: hello@clinika-os.ch

2. Data we collect

We collect the following categories of personal data:

  • Account data (controller): name, email, hashed password, clinic name, role
  • Clinic & billing data (controller): clinic name, address, timezone, subscription and payment data
  • Patient / clinical data (processor for the clinic): client identity and contact details, appointment details, and β€” where the clinic enables those features β€” clinical records that constitute health data (a special category, see Β§3)
  • Usage & security data (controller): access logs, browser and device type, error logs

3. Legal bases (including health data)

Where we are the controller we rely on contract performance (GDPR Art. 6(1)(b)), legitimate interests (Art. 6(1)(f) β€” security, fraud prevention, service improvement), legal obligation (Art. 6(1)(c)), and consent (Art. 6(1)(a)) for analytics cookies.

Health data is a special category under GDPR Art. 9, sensitive personal data under the Swiss revised FADP (revFADP), and is further governed in Portugal by Lei n.ΒΊ 58/2019. Where clinical/health data is processed, the clinic (as controller) is responsible for the special-category condition β€” typically Art. 9(2)(h) (health or social-care management under the responsibility of a health professional) and/or the patient's explicit consent (Art. 9(2)(a)). We process such data only as a processor on the clinic's instructions.

4. Data storage and security

All clinic and patient data is stored on servers located in Switzerland (Supabase, Zurich region). We use encryption in transit (TLS 1.2+) and at rest (AES-256) and row-level security to isolate each clinic's data. Where sub-processors operate outside Switzerland/the EEA, transfers are covered by appropriate safeguards β€” Standard Contractual Clauses and, for certified US providers, the EU–US Data Privacy Framework (see Β§7).

5. Data retention

Account & billing data (we are controller): retained for the life of the subscription plus the period required by law (up to 10 years, e.g. Swiss CO Art. 958f). Patient / clinical data (the clinic is controller): retention is configured and controlled by the clinic under the law applicable to it β€” for Portuguese clinics this is Portuguese health-record and tax law, not Swiss law. We hold such data while the clinic's account is active and delete or return it on termination per our DPA. Error logs are purged after 30 days.

6. Your rights

Under the GDPR, Swiss revFADP and β€” in Portugal β€” Lei n.ΒΊ 58/2019 you may access, rectify, erase, restrict, port and object, and withdraw consent. For account data, contact us. For patient/clinical data, direct the request to the clinic (the controller); we assist the clinic as its processor. We respond within 30 days.

Contact: hello@clinika-os.ch

7. Sub-processors

We use the following sub-processors under data-processing agreements:

  • Supabase (Zurich, Switzerland): database, authentication and file storage
  • Vercel: application hosting and CDN
  • Stripe (US β€” Data Privacy Framework): payment processing
  • Resend (US): transactional email delivery
  • Twilio (US): SMS appointment notifications (where a clinic enables SMS)
  • Sentry (US): application error monitoring (anonymised)
  • Google Analytics / Vercel Analytics: website analytics only (consent-gated / cookieless)

We keep a current sub-processor list and notify controllers of changes under the DPA.

8. Cookies

Strictly necessary cookies (session and authentication on the platform) cannot be disabled. Analytics cookies (website, consent only): Google Analytics 4, set only if you accept via the banner; withdrawable at any time. Performance monitoring: Vercel Analytics β€” anonymised, no cookies.

9. Data breach notification

For a breach that poses a risk to individuals we notify the Swiss FDPIC and, where applicable, the competent EU/EEA authority (e.g. the CNPD in Portugal) within 72 hours, and inform affected individuals where the risk is high. Where we are a processor, we notify the affected clinic(s) without undue delay. We keep an internal breach register.

10. Supervisory authorities, DPO & complaints

You may complain to your local authority β€” in Switzerland the FDPIC (www.edoeb.admin.ch); in Portugal the CNPD (www.cnpd.pt); or your EU/EEA local authority.

We keep our need for a formal Data Protection Officer under review; given that we process health data on behalf of clinics, we will appoint one if and when required. Clinics remain responsible for their own DPO obligations.

11. Data Processing Agreement

Our processing of patient/clinical data on behalf of clinics is governed by our Data Processing Agreement (GDPR Art. 28), which forms part of the Terms of Service.

12. Changes & contact

Material changes are notified to account holders at least 14 days in advance. Contact: hello@clinika-os.ch

Privacy Policy β€” Clinika OS | Clinika OS