Legal information
Privacy policy
Information about how SpineOn processes personal data when you use the website, book an appointment, administer visits, access admin authentication, receive transactional emails, use cookies, analytics, and related services.
Data Controller
The website, booking system, and related online services are operated by SpineOn klinik, s.r.o., Company ID: 57326860, Tax ID: 2122676457, with its registered office at Belá 6, 038 11 Belá-Dulice, Slovakia.
SpineOn klinik, s.r.o. is registered in the Commercial Register of the District Court Žilina, section Sro, file no. 89509/L.
Public website usage
When you browse the website, we process technical data needed to deliver pages, keep the service secure, operate the website, remember permitted settings, and display the correct language version.
Public pages may load technical resources needed to display the website, map, images, and related functionality.
Appointment booking and visit administration
When you book an appointment, we process the selected service, appointment date and time, name, e-mail, phone number, booking language, booking status, and technical data needed to create and administer the booking.
We use this data to create the booking, display availability, administer the appointment, communicate with you, send the booking confirmation, and notify the SpineOn team internally.
The public booking form does not require document uploads or a client account. If you voluntarily provide information about the reason for the visit by e-mail, phone, or an administration note, we process it only to the extent needed to organize the appointment and related communication.
Contact enquiries
The website currently does not contain a separate public free-text contact form. You can contact us by e-mail or phone; in that case we process the data you voluntarily provide.
If you contact us through the listed e-mail address or phone number, the message or call content is processed to handle the enquiry, manage follow-up communication, and, where relevant, organize an appointment.
Admin OTP and sessions
Admin access uses one-time login codes sent by e-mail. This process handles the admin e-mail address, OTP challenge, code hash, attempts, creation and expiry times, session token in hashed form, and security records needed to verify access.
Admin sessions use the necessary spineon_admin_session cookie and a database session record. These records are not intended for public clients.
Transactional emails
SpineOn sends necessary operational emails, mainly booking confirmations to clients, internal SpineOn team notifications, and admin OTP codes.
A booking confirmation may include the selected service, appointment time, name, e-mail, phone number, price, an organizational note, and an .ics calendar attachment with data needed to save the appointment.
Cookies, local storage, and referral attribution
Necessary cookies and storage support security, admin sessions, remembered cookie choices, booking administration, and abuse limitation.
If you arrive with a referral parameter, the browser may store a local spineon_referral record with the referral code, capture time, and landing path. When you later book an appointment, this data may be attached to the booking for internal source attribution.
Details about current cookies and browser storage are provided in the Cookie Policy.
Analytics and Google Maps
Hotjar loads only in production, only after analytics consent, and only on eligible public pages. The booking page, admin area, login, and more sensitive sections are excluded from Hotjar loading.
SpineOn does not load Google Analytics in the current application code.
The contact page contains an embedded Google Maps map. The map iframe uses a no-referrer policy so SpineOn does not send Google the full page URL or referral parameters. Google may still process technical data such as IP address, browser data, and map interactions when the map loads according to its own rules.
Purposes and legal bases
We process data mainly to operate the website, display availability, create and administer bookings, send confirmations, organize visits internally, answer enquiries, administer access, maintain security, comply with accounting and legal obligations, and improve the public website after analytics consent.
The legal basis is mainly taking steps before providing a service or performing a contract, compliance with legal obligations, legitimate interest in secure operation of the website and booking system, and consent where required, such as optional analytics. Where we process health-related data, we do so only to the extent needed and under the applicable legal basis for that category of data.
Processors and recipients
The table below lists the services used by the current SpineOn website. Services that the current website does not use are not listed in the table.
Access is limited to authorized persons and providers that need the data for the described purposes.
| Service / recipient | Purpose | Data categories | Role |
|---|---|---|---|
| Resend | Transactional email delivery, mainly booking confirmations, internal notifications, and admin OTP codes. | E-mail addresses, name and contact details, content needed for the message, .ics attachments, delivery metadata, and provider identifiers. | Processor |
| Vercel hosting, serverless runtime, CDN, and logs | Website hosting, server-side request processing, content delivery, deployments, availability, and security logging. | Technical request data, IP address, user agent, request identifiers, route, server response, and application data processed by server functions. | Processor |
| PostgreSQL database hosting used through Prisma and pg | Database storage for bookings, services, availability, admin users, OTP challenges, sessions, notification records, rate-limit records, and referral data. | Booking data, contact details, internal booking notes, security records, notification statuses, and referral attribution. | Processor |
| Hotjar / Contentsquare | Optional behavior analytics on public pages after analytics consent. | Eligible public-page visit data, device and browser technical data, _hj cookies or storage. Booking and admin areas are excluded. | Processor |
| Google Maps | Displaying the embedded SpineOn location map on the contact page. | Technical data needed to load the map, such as IP address, browser data, and map interactions. The map iframe is configured with a no-referrer policy. | Independent recipient or processor depending on Google services |
| Google / Gmail | Receiving and managing direct e-mail communication sent to the published spineonklinik@gmail.com address. | Sender e-mail address, message content, attachments, technical data, and delivery metadata. | Independent recipient or e-mail service provider |
Retention
Retention depends on the data type, purpose, security need, and legal obligations. We keep data for as long as reasonably necessary for the relevant purpose.
| Category | Typical retention period |
|---|---|
| Bookings and visit data | For as long as reasonably necessary to administer the appointment, manage follow-up communication, organize internally, resolve disputes, and meet legal or accounting obligations. |
| Contact enquiries by e-mail or phone | For as long as reasonably necessary to handle the enquiry, manage follow-up communication, and prove the related context. |
| OTP challenges, admin sessions, and authentication records | OTP challenges are short-lived where used for verification; related session and security records are retained for as long as reasonably necessary for security, audit, and operational purposes. |
| Rate-limit and abuse records | Records are used short-term for security and anti-abuse purposes depending on the check type; identity is stored in the database as a hashed key. |
| Booking notification logs | For as long as reasonably necessary to verify delivery, troubleshoot errors, operate the service internally, and prove that related communication was sent. |
| Cookie consent preferences | spineon_analytics_consent and spineon_marketing_consent are stored for up to 180 days unless you change the choice earlier. |
| Referral attribution | The local spineon_referral record remains in the browser until you remove it or clear browser data; attribution attached to a booking is retained with the booking record. |
| Hotjar analytics data | Retained according to Hotjar configuration and provider settings only after analytics consent. |
International transfers
Some providers may process data outside the European Economic Area. Where this happens, we rely on appropriate contractual and technical safeguards such as data processing agreements and standard contractual clauses where required.
The exact processing path can depend on provider configuration, routing, support, and infrastructure availability.
Your rights
Depending on the situation, you may request access to personal data, correction, deletion, restriction of processing, data portability, objection to processing, or withdrawal of consent where processing is based on consent.
We may need to verify your identity before acting on a request, especially for booking data or admin records.
Supervisory authority
If you believe your personal data is processed unlawfully, you may lodge a complaint with the Office for Personal Data Protection of the Slovak Republic.
We appreciate being contacted first so we can review and resolve your request.
Security
We use appropriate technical and organisational measures, such as admin OTP login, session cookies with security settings, rate limiting, access restrictions, security headers, no-store headers for admin, database audit records, and separation of analytics from more sensitive parts of the website.
No online service is completely risk-free. Measures are configured according to the sensitivity of processed data and the current website.
Children’s data
The website and booking system are not intended for independent use by children without appropriate involvement of a legal representative.
If we learn that a child’s data was provided without an appropriate reason or authority, we will restrict or delete it where required.
Automated decision-making
SpineOn does not make decisions with legal or similarly significant effects solely by automated means.
Analytics and internal operational records are used for measurement, security, organization, and website improvement, not for automated service-access decisions or professional assessment.
Data protection contact
For personal data questions or rights requests, you can contact us by e-mail at spineonklinik@gmail.com or by phone at +421 917 081 301.
