A clear summary of how Mediqa collects, uses, protects, and supports requests about personal data across the website, booking flows, and reserved product areas.
Scope
This notice applies to personal data processed through mediqa.it, demo requests, account registration, public booking pages, landing-demo calls, and the reserved SaaS workspace.
- It does not replace the privacy notice of a healthcare organization that uses Mediqa for its own patients.
- Operational patient data inside a customer workspace is normally processed by Mediqa on the customer's documented instructions.
Controller and processor roles
SCALEADS di Cristian Chiarelli, a sole proprietorship (VAT IT08833050720, Via Leonardo del Turco 4/E, 70128 Palese, Bari, Italy) trading as Mediqa, acts as controller for its website, demo requests, account setup, platform security, billing, commercial communications, and listening to the call recordings the caller said yes to, in order to improve the product and the service. For patient and workspace operations managed for a healthcare customer, the customer acts as controller and Mediqa acts as processor. That relationship is governed by the Article 28 processing agreement accepted by the healthcare organisation. Privacy requests can be sent to info@mediqa.it.
Data categories
Depending on the flow, Mediqa may process identification and contact data, organization data, account credentials, requested service, selected appointment slot, message or note content, booking references, call metadata, recordings and transcripts of phone calls, clinical records, reports and documents uploaded by the healthcare organisation, patient-portal activity, per-device sessions and second-factor events, consent markers, billing data, integration status, technical logs, audit events, and workspace configuration.
- Public forms ask users not to enter sensitive clinical data unless strictly necessary for the requested booking.
- If a user voluntarily includes health-related information in a booking or call context, it is handled only for the requested service flow and according to the applicable controller/processor role.
Health data and phone calls
When a healthcare organisation enables the AI phone assistant, calls handled by the assistant, including callbacks after an online form, are transcribed. At the start of every call the assistant says the call will be recorded and transcribed to improve the service and asks for consent to the recording: recording starts only after a yes, stops when the call is passed to a person at the organisation, and is kept for ninety days; it can be listened to by the organisation's owner and managers and by Mediqa staff โ on the organisation's behalf to support it, and as an independent controller to improve the product and the service โ and every listen is logged; if the caller says no, or gives no clear answer, the call is not recorded. Recordings are not used to train or improve AI models. A caller normally explains why they need an appointment, so a call can contain data concerning health under Article 9 GDPR. The same applies to clinical records, reports, and documents held inside a customer workspace.
- For these operations the healthcare organisation is the controller and Mediqa is the processor, and the legal basis is determined by that organisation. Recording retention โ ninety days, only with the caller's yes โ is the same for every organisation and is enforced by the platform; other data follows the organisation's written instructions. The one exception is listening to recordings to improve the product and the service: there Mediqa is an independent controller, and the legal basis is the caller's explicit consent (Article 6(1)(a) and Article 9(2)(a) GDPR), given with the yes at the start of the call; it can be withdrawn at any time, during the call by telling the assistant or afterwards by writing to info@mediqa.it.
- At the start of a call the assistant states that it is an artificial-intelligence assistant, says that the call is transcribed and asks whether it may be recorded; the spoken notice is part of the call script, not an optional add-on.
- Voice processing involves telephony and voice-AI providers, listed by name in the Article 28 data processing agreement. Clinical areas of the product are protected by role checks and multi-factor authentication.
If you are a patient
You may have reached this page because a clinic or dental practice you contacted uses Mediqa. In that case your controller is that practice: we hold your data on its behalf and follow its instructions. The one exception is the recording of your call, if you said yes to it: to listen to it in order to improve the product and the service, Mediqa is a controller too. What we may hold about you is what you gave the practice โ your contact details, your appointments, the call in which you asked for one, and any clinical documents the practice recorded.
- To see, correct, or delete your data, write to your practice first: it is the controller and can act on all of it. If you write to us, we will forward your request to the practice and tell you we have done so.
- Where the practice has enabled the patient portal, you can sign in and see your appointments and documents, correct your personal details, and cancel an appointment yourself.
- You can always lodge a complaint with the Garante per la protezione dei dati personali.
Purposes and legal bases
Data is processed to answer demo requests, create and protect accounts, provide the SaaS service, manage public bookings, route calls and follow-ups, send operational notifications, sync authorized calendars, process payments, prevent abuse, keep audit evidence, comply with legal obligations, and manage requested commercial contact.
- Main legal bases: pre-contractual steps, contract performance, legal obligations, legitimate interest in security and service reliability, and consent where the flow requires it.
- Whoever creates an organisation's account also gives us their mobile number, their role in the practice, and the practice's city: we use them only to set up the service and to call back if the setup stalls or needs help (pre-contractual steps and contract performance), never for marketing.
- Landing-demo recordings and commercial callbacks are handled only where the relevant consent marker is collected or otherwise legally available.
- Listening to recordings of calls with the phone assistant to improve the product and the service: the caller's explicit consent, given with the yes at the start of the call (Article 6(1)(a) and Article 9(2)(a) GDPR).
- Optional analytics and marketing tags on public marketing pages are based on consent and are blocked until that consent is given.
Retention
Personal data is kept for the time needed for the relevant purpose and then deleted, anonymized, or retained only where required for security, accounting, legal claims, audit, or contractual obligations. Customer workspace data follows the retention settings and written instructions agreed with the customer.
- Recordings of calls with the phone assistant: only with the caller's yes, for ninety days; without a yes the call is not recorded. The transcript is kept for ninety days by the voice provider; the copy in the organisation's records follows its instructions.
- Technical session and preference cookies follow the periods listed in the Cookie Policy.
- Billing records are kept for the statutory accounting period. Security and audit logs are retained only for proportionate control and incident-response needs.
Recipients and subprocessors
Depending on the enabled configuration, data may be processed by providers used for hosting, database and authentication, email delivery, telephony and voice AI, transcription of visit audio and assisted drafting of the clinical note, geocoding of practice addresses, calendar synchronization, payments, rate limiting, security, logging, support, and consent-based public-page measurement. Named here are only the services a visitor's own browser contacts from a public page, because those must be identifiable before they load: Calendly (demo booking, embedded on the public home page) and, only after consent, Google Analytics, Google Tag Manager, and Meta Pixel.
- Providers receive only the data needed for their function and are governed by contractual, technical, and organizational safeguards.
- The named, up-to-date list of subprocessors โ with each one's legal entity, region, and transfer basis โ is part of the Article 28 data processing agreement and is provided on request by writing to info@mediqa.it.
International transfers
Some providers may process data outside the European Economic Area depending on the chosen account, region, or service. Where this happens, Mediqa relies on applicable adequacy decisions, Standard Contractual Clauses, Data Processing Agreements, and supplementary safeguards where required.
User rights
Where applicable, individuals may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent by writing to info@mediqa.it. Requests related to a healthcare organization's workspace may be redirected to that organization when it acts as controller. Individuals may also lodge a complaint with the competent supervisory authority.
Security
Mediqa uses access controls, workspace separation, secure session handling, request guards, webhook signature checks where enforced, rate limiting where configured, audit-oriented logs, least-privilege service keys, and operational safeguards designed to protect platform and customer data.
Cookies and local storage
The application uses technical cookies and equivalent local/session storage for language, authentication, security, booking/demo handoff, and reserved-area usability. Optional support for Google Analytics 4, Google Tag Manager, and Meta Pixel is disabled by default, gated by environment configuration and granular consent, and limited to public marketing pages.
Certification readiness
A GDPR certification, where pursued, must be issued by an accredited certification body for a defined processing scope. This notice is one accountability document and must be kept aligned with the technical controls, processor agreements, retention schedule, and certification dossier.