The data controller responsible for your personal data is:
EndoAge may collect the following categories of personal data:
Identity & Contact Data:
- Full name, date of birth, gender identity
- Email address, phone number, country of residence
- Account credentials (username, hashed password)
Health & Medical Data (Special Category):
- Medical history, symptoms, diagnoses
- Laboratory results, biomarker data
- Medications, supplements, hormone therapies
- Lifestyle information (sleep, nutrition, exercise, stress)
- Health questionnaire responses
- Wearable device data (e.g., Apple Watch, Oura Ring, Dexcom, WHOOP, Garmin, Fitbit)
- Imaging or diagnostic reports uploaded by patients
- Consultation notes and clinical communications
Payment Data:
- Billing name and address
- Payment transaction identifiers (card details processed by third-party payment processors)
Technical Data:
- IP address, browser type, operating system
- Pages visited, session duration, referral source
- Cookie identifiers
EndoAge uses your personal data for the following purposes:
- To create and manage your patient account
- To deliver medical consultations, health assessments and longitudinal monitoring
- To calculate and present your EndoAge Score
- To generate AI-assisted health reports and personalized health roadmaps
- To facilitate telemedicine consultations
- To process payments and manage membership subscriptions
- To communicate appointment reminders, health updates and service information
- To comply with applicable legal and regulatory obligations
- To improve our services and develop new features (using anonymized data)
- To operate and maintain the security of our platform
4
Legal Basis for Processing
Processing of your personal data is carried out based on:
- Explicit Consent (Art. 6(1)(a) & Art. 9(2)(a) GDPR) — for processing special category health data
- Contract Performance (Art. 6(1)(b) GDPR) — for delivering healthcare services and managing your membership
- Legal Obligation (Art. 6(1)(c) GDPR) — for compliance with healthcare and data protection laws
- Legitimate Interests (Art. 6(1)(f) GDPR) — for platform security, fraud prevention, and service improvement (where interests are not overridden by your rights)
- Vital Interests (Art. 6(1)(d) GDPR) — in emergency situations where health or safety is at risk
EndoAge does not sell your personal data. Data may be shared only as follows:
- Healthcare professionals within the EndoAge network for clinical care
- Third-party laboratories for blood testing and diagnostics
- Payment processors for secure billing (PCI-DSS compliant)
- Cloud infrastructure providers for secure data hosting
- AI processing systems for report generation and health scoring
- Regulatory bodies or courts when legally required
All third-party processors are bound by data processing agreements and required to maintain confidentiality.
6
International Data Transfers
EndoAge primarily operates within the European Economic Area (EEA). Where data is transferred outside the EEA, we ensure appropriate safeguards are in place including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Data processing agreements with all international processors
- Medical records: Retained for a minimum of 10 years from the last patient interaction, or as required by applicable Romanian healthcare legislation
- Account data: Retained for the duration of your account and up to 3 years after closure, unless a longer period is required by law
- Financial records: Retained for 7 years for tax and accounting compliance
- Technical logs: Typically retained for 12 months
Data that is no longer necessary will be securely deleted or anonymized.
EndoAge implements appropriate technical and organizational measures to protect your data, including:
- Encryption of data in transit (TLS) and at rest
- Access controls and role-based permissions
- Regular security assessments and updates
- Staff training on data protection
- Incident response and breach notification procedures
No digital system is completely secure. In the event of a data breach affecting your rights, we will notify you and the relevant supervisory authority as required by GDPR.
You have the following rights regarding your personal data:
- Right of Access — obtain a copy of your data
- Right to Rectification — correct inaccurate or incomplete data
- Right to Erasure — request deletion where no longer necessary (subject to legal obligations)
- Right to Restrict Processing — limit how we use your data in certain circumstances
- Right to Data Portability — receive your data in a structured, machine-readable format
- Right to Object — object to processing based on legitimate interests or direct marketing
- Right to Withdraw Consent — withdraw consent at any time without affecting prior processing
- Right to Lodge a Complaint — with the Romanian Data Protection Authority (ANSPDCP) or any EU supervisory authority
To exercise any right, contact us at: endoageclinic@gmail.com
EndoAge uses cookies and similar tracking technologies to:
- Maintain your session and authentication status
- Remember your preferences
- Analyze website traffic and performance
You may control cookie preferences through your browser settings. Disabling certain cookies may affect platform functionality.
EndoAge services are intended for individuals aged 18 and over. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, please contact us immediately.
12
Changes to This Policy
EndoAge reserves the right to update this Privacy Policy at any time. Updated versions will be published on our website with a revised effective date. Continued use of our services after an update constitutes acceptance of the revised policy.
For privacy-related inquiries or to exercise your rights: