Versiunea în limba română

Privacy Policy — Sofimar Application

Effective version: 16 June 2026

1. Data controller

The data controller for the Sofimar mobile application (the "App") is:

Please use the email above for any request related to your personal data or to this policy.

2. About this policy

This policy describes what personal data we collect through the App, why we use it, who we share it with, how long we keep it, and your rights as a data subject under Regulation (EU) 2016/679 ("GDPR") and Romanian Law no. 190/2018.

The App processes health data (a special category of personal data under Article 9 GDPR). This data receives enhanced protection and is processed only for the purposes described below.

3. What data we collect

3.1 Data you provide directly

3.2 Data generated through your use of the App

3.3 What we do NOT collect

4. Why we use your data (purposes and legal basis)

PurposeData involvedLegal basis (GDPR)
Creating and managing your account Email, password, phone, name Art. 6(1)(b) — performance of a contract
Identity verification via CNP and ID-card OCR ID image, CNP, name Art. 6(1)(a) — explicit consent (initiated by you) and Art. 9(2)(h) — necessary for the provision of healthcare services
Medical appointments, medical letters, lab results CNP, medical data, appointments Art. 6(1)(b) and Art. 9(2)(h) — medical diagnosis and provision of healthcare
Sending notifications about your appointments, the status of appointment/availability processing, and new lab results (push notifications and on-device reminders) Push token; appointment and lab-result events. Notifications contain only generic text and never medical content. Art. 6(1)(b) — performance of a contract, and Art. 6(1)(f) — legitimate interest in keeping you informed
Automated interpretation of lab results (optional, on demand) Lab result document Art. 6(1)(a) and Art. 9(2)(a) — explicit consent
App security (abuse prevention, rate limits) UID, timestamps Art. 6(1)(f) — legitimate interest
Compliance with legal obligations (e.g. medical records) As required Art. 6(1)(c) — legal obligation

5. Who we share data with

We do not sell your data and we do not use it for advertising. We share it only with the following processors, strictly for the operation of the App:

ProcessorRoleData shared
Google LLC (Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Tasks) Cloud infrastructure for authentication, storage, and execution All account and medical data stored in the App
Google LLC — Cloud Vision API OCR on the ID document for CNP verification The ID image (transmitted temporarily; we do not retain it after processing)
Google LLC — Gemini API Automated interpretation of lab results, at your request The content of the lab result document
Expo (650 Industries, Inc.) Push notification delivery service, which relays our notifications to your device through Apple Push Notification service (iOS) and Firebase Cloud Messaging (Android) Your device push token and the generic notification text (no medical content)

For the Gemini API we use a paid Google Cloud subscription, which contractually provides that the data we submit is not used to train Google's models.

6. International data transfers

Our cloud functions and Firestore database run in the European Union (region europe-west8, Milan). Currently, uploaded files (medical letters, lab results) are stored on Firebase Storage in region US-EAST1 (United States). Additionally, Google Cloud Vision and Gemini services may process data outside the European Economic Area, and the Expo push notification service processes your device push token and the notification text in the United States.

These transfers rely on Google LLC's certification under the EU-US Data Privacy Framework and on the European Commission's Standard Contractual Clauses, providing a level of protection equivalent to that of the EU. We are actively working to move file storage fully to an EU region as options become available.

7. How long we keep your data

While your account is active, we retain account data and medical data. You may request deletion of your account at any time directly from the App (menu Account → Delete account) or through our Account and Data Deletion page. Upon account deletion:

We may retain an archived account marker and CNP reference only to match the correct clinic record, prevent record mismatches, and support verified restoration if you later create a new app account. Medical records and documents such as appointments, lab results, imaging results, medical letters, and prescriptions may be retained where required for healthcare, accounting, security, or legal obligations. These records are not accessible through the deleted app account and may be restored to a new app account only after CNP verification, where lawful. We will delete any additional app data that we are legally allowed to delete.

8. Your rights

As a data subject, under GDPR you have the following rights:

To exercise any of these rights, write to sofimar.ajutor@gmail.com. We will respond within 30 days.

9. Security

We use appropriate technical and organizational measures to protect your data: encryption in transit (HTTPS/TLS), encryption at rest in Google Cloud infrastructure, strict access rules in Firestore and Firebase Storage (each user can only see their own data), rate limits on sensitive operations (e.g. OCR), and uniqueness locks on the CNP to prevent identity impersonation.

10. Children

The App is not directed at persons under 16. We do not knowingly collect data from minors under that age. If we become aware that we have collected such data, we will delete it without undue delay.

11. Changes to this policy

We may update this policy as the App evolves. The effective version is shown at the top of the page. We will communicate significant changes through the App or by email before they take effect.

12. Contact

For any question, write to sofimar.ajutor@gmail.com or to SOFIMAR IMAGING SRL, Bdul. Laminorului no. 38, Floor 3, Apt. 9, Sector 1, Bucharest 012953, Romania.