Privacy Policy

XMED Platform – Effective from: April 8, 2026

1. Data controller details

Your personal data is processed by the following data controller:

XMED 360 Global Private Limited Liability Company

Registered seat: 1037 Budapest, Montevideo Street 7, 1st floor
Company Registration Number: 01-10-143096
Tax Number: 32702536-2-41
Email: contact@xmed360.com
Website: www.xmed360.com

XMED 360 Global Zrt. (hereinafter: "XMED" or "the Company") operates a digital healthcare service platform that enables users (patients) to book appointments online with healthcare providers, share documents, participate in video consultations, and use online payment services.

The data controller is responsible for the lawfulness of personal data processing, for ensuring the rights of data subjects, and for guaranteeing data security.

The detailed conditions for using the services are set out in the General Terms and Conditions (GTC), which are available on the data controller's website.

2. Definitions

For the purposes of this privacy policy, the following concepts are understood in accordance with the GDPR (EU Regulation 2016/679) and national legislation (particularly the Information Act):

  • personal data: any information relating to an identified or identifiable natural person;
  • data subject / user / patient: the natural person who uses the services of the XMED platform, including registered users and appointment bookers;
  • processing: any operation or set of operations performed on personal data, such as collection, recording, storage, modification, transmission, deletion;
  • data controller: the person or organization that determines the purposes and means of data processing;
  • data processor: a third party that processes personal data on behalf of the data controller;
  • health data: special data within the meaning of Article 9(1) of the GDPR, relating to the physical or mental health of a natural person;
  • joint controllers: organizations that jointly determine the purposes and means of data processing (e.g., XMED and the healthcare provider with whom the patient books an appointment).

3. Purpose, legal basis, and scope of data processing

XMED processes your personal data only for pre-determined, lawful purposes and to the extent necessary for those purposes.

Processing purposeScope of data processedLegal basis
User registration, account creationName, email address, password, phone numberPerformance of a contract (GDPR Art. 6(1)(b))
Appointment booking and communicationSelected provider, appointment, message, notification settingsPerformance of a contract
Uploading and sharing health documentsTest results, discharge summaries, examination materialsExplicit consent (GDPR Art. 9(2)(a))
Conducting video consultation, recordingAudio and video recording, verbatim transcriptConsent to recording + contract for transcript
Billing, payment, accountingName, address, email, payment data (tokenized)Legal obligation (under the Accounting Act)
Complaint handling, feedbackComplaint content, contact details, communication historyLegitimate interest (GDPR Art. 6(1)(f))
Marketing and newsletter sendingName, email, preferencesConsent (GDPR Art. 6(1)(a))
Automatic receipt of lab results and making them available to prepare for video consultationData subject's lab results and test results from the past 90 days, identification dataData subject's explicit consent (GDPR Art. 6(1)(a)), and for health data, GDPR Art. 9(2)(a))

The recording of video consultations is not mandatory and takes place only with the patient's prior, voluntary consent. The recorded material is retained for a maximum of 30 days, only until the verbatim transcript is prepared. The transcript becomes part of the medical documentation, and the recording is automatically deleted thereafter. (GTC, point 16)

3.1. Data processing on behalf of another person and processing of minors' data

  • The XMED Platform allows the User to register or book an appointment on behalf of another person — particularly a minor child, relative, or ward.
  • In such cases, the User is required to declare that they have legal representation or authorization to act on behalf of the other person.
  • Due to the technical operation of the Platform, XMED cannot verify the existence of the right of representation, so the User's declaration serves as the basis for data processing.
  • The XMED professional is entitled to request proof of legal representation before the consultation begins.
  • The legal representative bears full responsibility for the registration made on behalf of another person, the accuracy of the data provided, and the data processing declarations.
  • XMED does not assume responsibility for any data processing initiated by the User without authorization, not based on a genuine right of representation.

3.2. Consent to automatic receipt of lab results

If the User books an appointment for an online consultation following a laboratory test, the Platform allows XMED, based on the User's explicit consent, to receive the data subject's lab results from the past 90 days from the SYNLAB Hungary Kft. IT system via a direct API connection.

Providing consent is not a prerequisite for using the Platform; if consent is not given, the User is entitled to manually upload lab results.

The User acknowledges that due to the operation of SYNLAB's IT system, the data transfer cannot technically be limited to selected results but covers all lab results produced in the given period.

4. Data processing related to the operation of the application

The XMED Platform is available both as a mobile application and a web interface. The data processing necessary for using the services is defined in point 3 of this policy; however, due to the operation of the application, additional technical data processing also takes place.

4.1. Handling of technical data

During the use of the application, technical data necessary for the operation and security of the system may be automatically recorded, including in particular:

  • the type of device running the application and the operating system version,
  • the application version,
  • system usage and error reporting (log) data.

4.2. Data connections and data flow

To provide the services, the application maintains a continuous connection with XMED's IT systems. Such data connections occur in particular in the following cases:

  • during appointment booking, to the system of the relevant healthcare provider,
  • during online payment, to the system of the payment provider,
  • during automatic receipt of lab results, to the system of SYNLAB Hungary Kft.

4.3. Integration with third-party systems

Within the framework of these integrations, data may be transferred in particular to: healthcare providers to ensure care, laboratory providers (e.g., SYNLAB Hungary Kft.), payment providers to facilitate online payments, and IT providers to operate the system. Data transfer is always limited to what is necessary.

4.4. In-app information and consent

For certain data processing operations — particularly the processing of health data, automatic receipt of lab results, and recording of video consultations — the Platform displays separate in-app information.

4.5. Principle of data minimization in application operation

When providing its services, XMED processes only the data necessary for the operation of the given function and always strives to minimize data processing.

4.6. Background data collection and use of third-party SDKs

The XMED Platform processes data only in connection with operations initiated by the User. The application does not perform continuous or background data collection without the User's knowledge and does not use any third-party analytics or advertising software development kits (SDKs) designed to track the User's behavior.

5. Purposes of data use

The Company uses personal data only for specified, explicit, and lawful purposes.

5.1. Service provision

  • creation and management of user accounts,
  • appointment booking and its administration,
  • conducting video consultations,
  • management and availability of health documents,
  • receipt and display of lab results.

5.2. Communication with the User

  • sending notifications related to appointments,
  • forwarding system messages and information,
  • customer service communication.

Marketing communications are sent only based on the User's separate consent.

5.3. Ensuring service security and operation

  • identifying and handling technical errors,
  • monitoring system usage,
  • preventing abuse.

5.4. Fulfillment of legal obligations

  • accounting and tax obligations,
  • regulations concerning medical documentation.

5.5. Marketing and related communication

  • sending newsletters,
  • communicating offers related to services.

5.6. Limitation of data use

The Company does not use personal data for the purpose of independent commercial sale to third parties, for automated decision-making or profiling (unless permitted by specific legislation or explicit consent). The Company does not sell personal data and does not use them for targeted advertising activities for third parties.

6. Legal bases of data processing

XMED processes your personal data only on the legal bases defined by the GDPR (Regulation 2016/679 of the European Parliament and of the Council).

a) Performance of a contract (GDPR Art. 6(1)(b))

  • creation of a user account,
  • appointment booking,
  • conducting video consultations,
  • billing.

b) Fulfillment of a legal obligation (GDPR Art. 6(1)(c))

  • retention of accounting data (under §169 of the Accounting Act),
  • documentation of health data, where XMED participates as a joint controller.

c) Consent (GDPR Art. 6(1)(a) and Art. 9(2)(a))

  • uploading health documents to the system,
  • recording video consultations,
  • marketing, newsletter sending.

Consent can be withdrawn at any time in the user account or by email, without affecting the lawfulness of the prior data processing.

d) XMED's legitimate interest (GDPR Art. 6(1)(f))

  • documentation of complaint handling,
  • maintaining system security,
  • technical logging, prevention of abuse.

Data processing based on legitimate interest is always preceded by a balancing of interests test.

7. Data transfer and data processors

7.1. Data processors

PartnerRole
eHealth Software Solutions Kft.Platform development, system operation
Appon Line Kft.Platform development, system operation
Invitech ICT Services Kft.Hosting, technical infrastructure
Amazon Web Services EMEA SARLHosting, technical infrastructure
Rackforest Zrt.Hosting, technical infrastructure
Whereby ASHosting, technical infrastructure
OTP Mobil Kft. (SimplePay)Online payment processing
Microsoft Ireland Operations Ltd.Microsoft 365 services
Accounting firmAccounting, tax administration

These partners always act on the basis of a written data processing agreement in accordance with Article 28 of the GDPR.

7.2. Joint controllers

If you book an appointment with a contracted healthcare provider through the XMED interface, that institution qualifies as a joint controller together with XMED. In such cases, both parties have access to the patient's data, the consultation documentation and certain health data are shared, and the purpose and method of data processing are determined jointly.

Key joint controller: SYNLAB Hungary Kft. – laboratory tests and customer service support. The detailed conditions of the joint data processing are regulated by a separate agreement between the parties.

The complete list of contracted partners is available in Annex 1 of the GTC.

8. Data retention periods

XMED stores your data only for the purpose-bound period and in compliance with legal obligations.

Data typeRetention period
Registration dataUntil deletion of the user account, but at most 5 years after inactivity
Appointment booking data5 years from the booking date
Video consultation recordingMaximum 30 days, only until the transcript is prepared
Consultation transcript5 years (as medical documentation)
Billing data8 years (under the Accounting Act)
Complaint handling documents5 years
Health documentsDuring the active existence of the user account, or until withdrawal
Marketing dataUntil withdrawal, but deleted after at most 2 years of inactivity
Lab results (automatically received)During the active existence of the user account, or until withdrawal of consent

9. Data subject rights and their exercise

9.1. Your rights:

  • Right of access (GDPR Art. 15): you are entitled to request information about whether we process your personal data, and if so, for what purpose, what types of data are involved, how long we store them, to whom we transfer them, etc.
  • Right to rectification (GDPR Art. 16): you may request the correction of inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten", GDPR Art. 17): you may request the deletion of your personal data if, for example, you withdraw your consent or the data is no longer needed.
  • Right to restriction of processing (GDPR Art. 18): you may request that we block your data if you dispute its accuracy or object to the processing.
  • Right to data portability (GDPR Art. 20): you are entitled to receive the data you provided in a structured, machine-readable format.
  • Right to object (GDPR Art. 21): you are entitled to object to data processing based on the legal basis of legitimate interest.
  • Withdrawal of consent (GDPR Art. 7(3)): if the data processing was based on consent, you may withdraw it at any time.

9.2. How to exercise your rights:

  • by email: contact@xmed360.com
  • by post: 1037 Budapest, Montevideo Street 7, 1st floor
  • via the AI chat interface: the XMED platform's built-in chatbot also allows you to submit a complaint or rights exercise request.

We will respond within a maximum of 30 days from receipt of the request. If it is not possible to respond within this deadline, we will send a separate notification.

10. Principles of data security

XMED places particular emphasis on the security of personal data and applies appropriate technical and organizational measures to prevent unauthorized access, loss, destruction, or alteration of data.

10.1. Applied measures include:

  • encrypted data transmission (SSL/TLS),
  • two-factor administrator login,
  • role-based access,
  • regular backups and intrusion prevention controls,
  • data breach management protocol.

10.2. Obligations of subcontractors:

We enter into a written agreement with all our data processors, requiring them to maintain data security measures compliant with the GDPR.

11. Remedies options

11.1. Filing a complaint with the data controller:

  • email: contact@xmed360.com
  • via the AI chatbot

11.2. Filing a complaint with the supervisory authority:

National Authority for Data Protection and Freedom of Information (NAIH)

Address: 1055 Budapest, Falk Miksa Street 9–11.

Phone: +36 1 391 1400

Email: ugyfelszolgalat@naih.hu

Web: www.naih.hu

11.3. Court action:

You may turn to the courts if, in your assessment, XMED or any data controller has violated your rights relating to personal data. The proceedings may be initiated before the court of your domicile or place of residence.

11.4. Unauthorized data processing on behalf of another person

If it arises in connection with data processing that the User acted without authorization on behalf of another person, XMED is entitled to restrict the data processing, inform the affected party and — if necessary — the competent authority (NAIH).

12. Validity and modification of the policy

This privacy policy is effective from April 8, 2026, and remains valid until withdrawn.

XMED reserves the right to modify this policy unilaterally, particularly in the event of legislative changes, new data processing purposes, or technological developments.

The modified policy enters into force upon publication on the platform, and registered users are notified of it electronically (by email).