Legal information

Privacy policy

Information about how SpineOn processes personal data when you use the website, book an appointment, administer visits, access admin authentication, receive transactional emails, use cookies, analytics, and related services.

Data Controller

The website, booking system, and related online services are operated by SpineOn klinik, s.r.o., Company ID: 57326860, Tax ID: 2122676457, with its registered office at Belá 6, 038 11 Belá-Dulice, Slovakia.

SpineOn klinik, s.r.o. is registered in the Commercial Register of the District Court Žilina, section Sro, file no. 89509/L.

Public website usage

When you browse the website, we process technical data needed to deliver pages, keep the service secure, operate the website, remember permitted settings, and display the correct language version.

Public pages may load technical resources needed to display the website, map, images, and related functionality.

Appointment booking and visit administration

When you book an appointment, we process the selected service, appointment date and time, name, e-mail, phone number, booking language, booking status, and technical data needed to create and administer the booking.

We use this data to create the booking, display availability, administer the appointment, communicate with you, send the booking confirmation, and notify the SpineOn team internally.

The public booking form does not require document uploads or a client account. If you voluntarily provide information about the reason for the visit by e-mail, phone, or an administration note, we process it only to the extent needed to organize the appointment and related communication.

Contact enquiries

The website currently does not contain a separate public free-text contact form. You can contact us by e-mail or phone; in that case we process the data you voluntarily provide.

If you contact us through the listed e-mail address or phone number, the message or call content is processed to handle the enquiry, manage follow-up communication, and, where relevant, organize an appointment.

Admin OTP and sessions

Admin access uses one-time login codes sent by e-mail. This process handles the admin e-mail address, OTP challenge, code hash, attempts, creation and expiry times, session token in hashed form, and security records needed to verify access.

Admin sessions use the necessary spineon_admin_session cookie and a database session record. These records are not intended for public clients.

Transactional emails

SpineOn sends necessary operational emails, mainly booking confirmations to clients, internal SpineOn team notifications, and admin OTP codes.

A booking confirmation may include the selected service, appointment time, name, e-mail, phone number, price, an organizational note, and an .ics calendar attachment with data needed to save the appointment.

Cookies, local storage, and referral attribution

Necessary cookies and storage support security, admin sessions, remembered cookie choices, booking administration, and abuse limitation.

If you arrive with a referral parameter, the browser may store a local spineon_referral record with the referral code, capture time, and landing path. When you later book an appointment, this data may be attached to the booking for internal source attribution.

Details about current cookies and browser storage are provided in the Cookie Policy.

Analytics and Google Maps

Hotjar loads only in production, only after analytics consent, and only on eligible public pages. The booking page, admin area, login, and more sensitive sections are excluded from Hotjar loading.

SpineOn does not load Google Analytics in the current application code.

The contact page contains an embedded Google Maps map. The map iframe uses a no-referrer policy so SpineOn does not send Google the full page URL or referral parameters. Google may still process technical data such as IP address, browser data, and map interactions when the map loads according to its own rules.

Purposes and legal bases

We process data mainly to operate the website, display availability, create and administer bookings, send confirmations, organize visits internally, answer enquiries, administer access, maintain security, comply with accounting and legal obligations, and improve the public website after analytics consent.

The legal basis is mainly taking steps before providing a service or performing a contract, compliance with legal obligations, legitimate interest in secure operation of the website and booking system, and consent where required, such as optional analytics. Where we process health-related data, we do so only to the extent needed and under the applicable legal basis for that category of data.

Processors and recipients

The table below lists the services used by the current SpineOn website. Services that the current website does not use are not listed in the table.

Access is limited to authorized persons and providers that need the data for the described purposes.

Service / recipientPurposeData categoriesRole
ResendTransactional email delivery, mainly booking confirmations, internal notifications, and admin OTP codes.E-mail addresses, name and contact details, content needed for the message, .ics attachments, delivery metadata, and provider identifiers.Processor
Vercel hosting, serverless runtime, CDN, and logsWebsite hosting, server-side request processing, content delivery, deployments, availability, and security logging.Technical request data, IP address, user agent, request identifiers, route, server response, and application data processed by server functions.Processor
PostgreSQL database hosting used through Prisma and pgDatabase storage for bookings, services, availability, admin users, OTP challenges, sessions, notification records, rate-limit records, and referral data.Booking data, contact details, internal booking notes, security records, notification statuses, and referral attribution.Processor
Hotjar / ContentsquareOptional behavior analytics on public pages after analytics consent.Eligible public-page visit data, device and browser technical data, _hj cookies or storage. Booking and admin areas are excluded.Processor
Google MapsDisplaying the embedded SpineOn location map on the contact page.Technical data needed to load the map, such as IP address, browser data, and map interactions. The map iframe is configured with a no-referrer policy.Independent recipient or processor depending on Google services
Google / GmailReceiving and managing direct e-mail communication sent to the published spineonklinik@gmail.com address.Sender e-mail address, message content, attachments, technical data, and delivery metadata.Independent recipient or e-mail service provider

Retention

Retention depends on the data type, purpose, security need, and legal obligations. We keep data for as long as reasonably necessary for the relevant purpose.

CategoryTypical retention period
Bookings and visit dataFor as long as reasonably necessary to administer the appointment, manage follow-up communication, organize internally, resolve disputes, and meet legal or accounting obligations.
Contact enquiries by e-mail or phoneFor as long as reasonably necessary to handle the enquiry, manage follow-up communication, and prove the related context.
OTP challenges, admin sessions, and authentication recordsOTP challenges are short-lived where used for verification; related session and security records are retained for as long as reasonably necessary for security, audit, and operational purposes.
Rate-limit and abuse recordsRecords are used short-term for security and anti-abuse purposes depending on the check type; identity is stored in the database as a hashed key.
Booking notification logsFor as long as reasonably necessary to verify delivery, troubleshoot errors, operate the service internally, and prove that related communication was sent.
Cookie consent preferencesspineon_analytics_consent and spineon_marketing_consent are stored for up to 180 days unless you change the choice earlier.
Referral attributionThe local spineon_referral record remains in the browser until you remove it or clear browser data; attribution attached to a booking is retained with the booking record.
Hotjar analytics dataRetained according to Hotjar configuration and provider settings only after analytics consent.

International transfers

Some providers may process data outside the European Economic Area. Where this happens, we rely on appropriate contractual and technical safeguards such as data processing agreements and standard contractual clauses where required.

The exact processing path can depend on provider configuration, routing, support, and infrastructure availability.

Your rights

Depending on the situation, you may request access to personal data, correction, deletion, restriction of processing, data portability, objection to processing, or withdrawal of consent where processing is based on consent.

We may need to verify your identity before acting on a request, especially for booking data or admin records.

Supervisory authority

If you believe your personal data is processed unlawfully, you may lodge a complaint with the Office for Personal Data Protection of the Slovak Republic.

We appreciate being contacted first so we can review and resolve your request.

Security

We use appropriate technical and organisational measures, such as admin OTP login, session cookies with security settings, rate limiting, access restrictions, security headers, no-store headers for admin, database audit records, and separation of analytics from more sensitive parts of the website.

No online service is completely risk-free. Measures are configured according to the sensitivity of processed data and the current website.

Children’s data

The website and booking system are not intended for independent use by children without appropriate involvement of a legal representative.

If we learn that a child’s data was provided without an appropriate reason or authority, we will restrict or delete it where required.

Automated decision-making

SpineOn does not make decisions with legal or similarly significant effects solely by automated means.

Analytics and internal operational records are used for measurement, security, organization, and website improvement, not for automated service-access decisions or professional assessment.

For personal data questions or rights requests, you can contact us by e-mail at spineonklinik@gmail.com or by phone at +421 917 081 301.