Privacy Notice

MDExpert Clinic Kft. – mdexpertclinic.hu
In force from: 9 September 2026 · Version: 1.2

Language note. This document is an English translation of the Hungarian privacy notice (Privacy Policy) published at mdexpertclinic.hu/adatkezelesi-tajekoztato. It is provided for information purposes. In the event of any discrepancy between the two language versions, the Hungarian text prevails.

1. Introduction

MDExpert Clinic Korlátolt Felelősségű Társaság (hereinafter: the Controller or the Clinic) attaches particular importance to processing the personal data of visitors to the mdexpertclinic.hu website (hereinafter: the Website), as well as of its patients, clients and enquirers, in a lawful, secure and transparent manner.

The purpose of this notice is to give data subjects clear and plain information, before they provide any personal data, about what data the Controller processes, for what purpose, on what legal basis, for how long, to whom it discloses that data, and what rights data subjects may exercise.

This notice has been prepared having regard to the following legislation:

2. Details of the Controller

Company nameMDExpert Clinic Korlátolt Felelősségű Társaság
Registered office and place of care5 Rétköz Street, 1118 Budapest, Hungary
Company registration number01 09 451905
Tax number32447354-2-43
Healthcare service provider licence number011595
Represented byLászló Kecskeméti, managing director
Telephone+36 70 676 5885
E-mailclinic@mdexpert.hu
Websitehttps://mdexpertclinic.hu

2.1. Data Protection Officer (DPO)

As a healthcare provider processing health data on a large scale, the Controller has designated a Data Protection Officer pursuant to Article 37 GDPR, whom data subjects may contact directly on any matter relating to the processing of their personal data and the exercise of their rights:

NameTímea Kálmán
E-mailclinic@mdexpert.hu
Postal address5 Rétköz Street, 1118 Budapest, Hungary

3. Definitions

Personal data: any information relating to an identified or identifiable natural person (the "data subject"), such as name, e-mail address, telephone number or IP address.

Health data: personal data related to the physical or mental health of the data subject, including information on the use of healthcare services (for example the type of treatment requested, complaints, previous interventions, allergies, photographs of the treated area). This is a special category of data under Article 9 GDPR and enjoys enhanced protection.

Processing: any operation performed on personal data (collection, recording, storage, transmission, erasure, etc.).

Controller: the party determining the purposes and means of the processing, in this case the Clinic.

Processor: a party processing personal data on behalf of and on the instructions of the Controller (for example a hosting provider, a booking system or a newsletter platform).

Consent: a freely given, specific, informed and unambiguous indication of the data subject's wishes.

4. Principles of processing

The Controller processes personal data lawfully, fairly and transparently, exclusively for specified, explicit and legitimate purposes (purpose limitation); requests only the data necessary to achieve that purpose (data minimisation); ensures the accuracy of the data; stores it only for as long as necessary (storage limitation); and safeguards the confidentiality, integrity and availability of the data by appropriate technical and organisational measures (integrity and confidentiality).

When processing health data, the Controller also fully complies with the Eüak.: health data is processed solely for the purpose of healthcare provision, to the extent necessary for that purpose, and is made accessible only to the treating physician and to the persons involved in the care who are bound by professional secrecy.

5. Individual processing activities

5.1. Appointment and consultation requests on the Website

Through the forms available on the Website, enquirers may request an appointment or a consultation for the Clinic's services.

Data processedfamily and given name; e-mail address; telephone number; the treatment area or service requested; the chosen physician; preferred date; the free-text content of the message; the answer to "how did you hear about us"; the time of submission and the sender's IP address.
Health dataThe treatment area requested, together with any information on state of health voluntarily provided by the data subject in the message, qualifies as health data.
PurposeArranging an appointment, contacting the data subject, preparing the provision of the healthcare service; in the case of the "how did you hear about us" answer, measuring the effectiveness of the Clinic's marketing activity (statistical evaluation, not individual assessment).
Legal basisPersonal data: Article 6(1)(b) GDPR – steps taken at the request of the data subject prior to entering into a contract (healthcare provision).
Health data: Article 9(2)(h) GDPR – provision of health care, in conjunction with Section 4(1) of the Eüak.; the processing is carried out by a healthcare professional bound by professional secrecy (Article 9(3) GDPR).
"How did you hear about us": Article 6(1)(f) GDPR – the legitimate interest of the Controller (measuring marketing effectiveness).
RetentionIf no care relationship is established: 1 year from the closure of the booking or enquiry, after which the data is erased.
If care is provided: the data becomes part of the medical records and is retained for at least 30 years from the date of recording, pursuant to Section 30 of the Eüak.
Provision of dataVoluntary; however, without the data marked with an asterisk the booking cannot be completed.
ProcessorsHosting provider; MiniCRM Zrt. (customer relationship management system) – see Section 6.

5.2. Online appointment booking via the MyMedio system

From the Website, users may proceed to the online booking interface available at mdexpertclinic.mymedio.hu, where the data subject may independently select an available appointment.

Data processedname; e-mail address; telephone number; date of birth, where requested by the booking interface; the selected service and physician; the appointment; the status of the booking; the log of confirmation and reminder messages sent by the system.
PurposeBooking and confirming an appointment, sending reminders (e-mail/SMS), organising the daily operation of the practice.
Legal basisArticle 6(1)(b) GDPR – preparation and performance of a contract; as regards the selected service qualifying as health data, Article 9(2)(h) GDPR and Section 4(1) of the Eüak.
RetentionAs set out in Section 5.1.
ProcessorMedio MedTech Zrt. (MyMedio) – see Section 6. MyMedio's own privacy notice concerning the use of the interface is available on the booking interface.

5.3. Contact by e-mail, telephone or social media

Data processedname; e-mail address; telephone number; the content of the enquiry and any other data voluntarily disclosed therein by the data subject; the time of the enquiry.
PurposeAnswering the data subject's question, providing information, maintaining contact.
Legal basisArticle 6(1)(f) GDPR – the legitimate interest of the Controller and the data subject in having the enquiry answered; where the enquiry concerns the use of a service, Article 6(1)(b) GDPR. Where health data is disclosed, Article 9(2)(h) GDPR.
Retention1 year from the closure of the enquiry; if care is provided, in accordance with the retention period for medical records.

The Controller does not record telephone calls.

5.4. Newsletter and marketing communications

Data subjects may subscribe to the Clinic's newsletter by ticking the "I would like to receive news from the clinic" checkbox on the Website's forms, or by signing a paper declaration at the Clinic.

Data processedname; e-mail address; telephone number (in the case of SMS messages); the time and manner of subscription (IP address); statistics on the opening of newsletters and on clicks on the links contained in them.
PurposeSending electronic information and advertising messages about the Clinic's news, new services, promotions and events; measuring the effectiveness of the newsletters.
Legal basisArticle 6(1)(a) GDPR – the voluntary consent of the data subject, in conjunction with Section 6(1)–(2) of the Grt. The Controller does not use health data for the purpose of sending newsletters: the content of the newsletter is not personalised on the basis of the treatments used by the data subject.
RetentionUntil consent is withdrawn (unsubscription). Unsubscription may be effected at any time, without giving reasons and free of charge, via the link in the footer of the newsletter or by sending a message to clinic@mdexpert.hu. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
ProcessorMiniCRM Zrt. – see Section 6.

5.5. The Clinic's social media pages (Facebook, Instagram)

The Controller operates a Facebook page and an Instagram page. Content published by visitors to those pages (comments, messages, likes) is processed by the Controller for the purposes of contact and information, on the legal basis of Article 6(1)(f) GDPR (legitimate interest). With regard to the visitor statistics of the pages ("Page Insights"), the Controller and Meta Platforms Ireland Ltd. qualify as joint controllers; the arrangement determining their respective responsibilities is available at https://www.facebook.com/legal/terms/page_controller_addendum. The Clinic asks that no one publicly share information concerning their state of health on social media platforms; such matters may be raised with the Clinic at clinic@mdexpert.hu or by telephone.

5.6. Data processed in the course of healthcare provision (at the Clinic)

Following a booking made on the Website, in the course of the healthcare service used at the Clinic the Controller maintains medical records with the content prescribed by law (medical history, examination findings, treatment plan, consent declarations, photographic documentation of the treated area, products used, data of follow-up examinations). Data subjects receive a separate, detailed patient information notice on this processing at the Clinic upon their first attendance, which supplements this notice.

Legal basisArticle 6(1)(b) and (c) GDPR; Article 9(2)(h) GDPR – healthcare provision, and the documentation obligation under the Eütv. and the Eüak.
RetentionSection 30(1)–(2) of the Eüak.: medical records are to be retained for at least 30 years from the date of recording, discharge summaries for at least 50 years, diagnostic imaging recordings for 10 years and the findings prepared from them for 30 years.
DisclosureIn the cases prescribed by law, to the Electronic Health Service Space (EESZT); at the request of the data subject, to another healthcare provider; upon a statutory request from an authority or court.

5.7. Invoicing

Data processedbilling name and address; the name of the service; amount; method of payment; invoice serial number and date. The invoice does not contain health data (diagnosis).
Purpose, legal basisIssuing and retaining accounting documents – Article 6(1)(c) GDPR, Section 169(2) of the Accounting Act, Section 169 of the VAT Act.
Retention8 years from the issue of the invoice.
ProcessorsThe provider of the invoicing software and the bookkeeper – see Section 6.

5.8. Complaint handling

Data processedthe name and contact details of the complainant; the content of the complaint and the service concerned; the record taken of the complaint and the letter of reply.
Purpose, legal basisInvestigating and answering the complaint – Article 6(1)(c) GDPR, Section 17/A of the Fgytv.; in the case of a complaint concerning healthcare, Section 29 of the Eütv.
Retention3 years from the recording of the complaint (Section 17/A(7) of the Fgytv.); documents relating to a complaint connected with healthcare provision are retained as part of the medical records.

5.9. Electronic surveillance system (CCTV) at the Clinic

The Controller operates a camera surveillance system at the reception, in the corridor and at the entrance of the Clinic for property protection purposes. No camera operates in treatment rooms. Legal basis: Article 6(1)(f) GDPR – the legitimate interest of the Controller (protection of property and persons). In the absence of any use, the Controller erases the recordings after 3 days from recording and in any event within 30 days. Information on the camera surveillance is provided by a pictogram and a detailed notice displayed at the entrance.

5.10. Cookies, consent management and website analytics

In addition to the cookies strictly necessary for its operation, the Website – solely with the prior consent of the data subject – uses website analytics, user-behaviour analysis and social media content tools. Consent may be given via the cookie notice displayed on the first visit; non-essential tools are technically prevented from running and do not set any cookies before consent is given.

Cookie categoriesNecessary – essential for the operation of the site and cannot be switched off (security, forms, language selection, the online booking window, the chat assistant, storage of the cookie choice).
Statistics – visitor and behaviour measurement (Google Analytics 4, Microsoft Clarity, WooCommerce visitor-source tracking).
Marketing / social media – social content displayed by a third-party provider (Elfsight Instagram feed).
Giving and withdrawing consentThe “Accept all”, “Necessary only” and per-category “Settings” options are offered on an equal footing. The choice may be changed or withdrawn at any time by clicking the “Cookie settings” link in the footer of the Website; upon withdrawal the Website deletes the cookies of the category concerned and the associated tools are stopped. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Tools usedGoogle Analytics 4 (measurement ID: G-TP9WZT1EXP) – visitor and traffic statistics; through Google “Consent Mode v2”, no measurement or advertising-related processing takes place until consent is given.
Microsoft Clarity (project ID: yg3fc2j8nv) – aggregated usage statistics, heatmaps and session recordings capturing mouse movement, scrolling and clicks.
WooCommerce visitor-source tracking (Sourcebuster) – the Website's own first-party tool that records the source of the visit (referring page, campaign parameters) and the number of pages viewed in the session; no data is transferred to third parties.
Elfsight Instagram feed – a widget of Elfsight PTE. LTD. displaying the Clinic's Instagram posts; when loaded, the visitor's IP address and browser data reach the servers of Elfsight and Instagram (Meta), and those providers may set their own cookies.
Data processedthe time and duration of the visit; the pages viewed; the referring source and campaign parameters; the type of device, browser and operating system used; approximate geographical location (country, city); truncated IP address; in the case of Clarity, a recording of the visitor's interactions within the page; in the case of the Instagram widget, the IP address and browser identifiers transmitted on loading.
Data entered into formsClarity masks the content of input fields by default, meaning that text entered by the visitor (including any information concerning their state of health) does not appear in the recording. The Controller keeps masking enabled.
PurposeUnderstanding the use of the Website, improving content and user experience, detecting errors, and displaying the Clinic's social media content. The Controller does not identify individual visitors on the basis of this data and does not take decisions producing legal effects concerning the data subject.
Legal basisNecessary cookies: Article 6(1)(f) GDPR – the Controller's legitimate interest in the secure operation of the Website, and Section 13/A(3) of the Hungarian E-commerce Act. Statistics and marketing categories: Article 6(1)(a) GDPR – the consent of the data subject, given through the cookie notice.
RetentionGoogle Analytics: event data for a maximum of 14 months. Microsoft Clarity: session recordings for a maximum of 30 days, aggregated statistics for a maximum of 13 months. Visitor-source tracking: until the end of the session or a maximum of 30 days. Consent record cookie: 12 months. The expiry of each cookie is set out in the table below.
Processors, recipientsGoogle Ireland Limited; Microsoft Ireland Operations Limited; Elfsight PTE. LTD.; Meta Platforms Ireland Limited (Instagram content) – see Sections 6 and 7.

Cookies used on the Website

Cookie nameProviderCategoryPurposeExpiry
mdx_consentMDExpert Clinic (first party)NecessaryStores the visitor's cookie choice so that the notice is not shown on every page load12 months
woocommerce_*, wp_woocommerce_session_*, wordpress_test_cookieMDExpert Clinic (first party)NecessaryTechnical session cookies required by the website enginesession / up to 2 days
_gaGoogle Analytics 4StatisticsDistinguishes visitors using a random identifier2 years
_ga_PYS8KYE6N6Google Analytics 4StatisticsMaintains session state2 years
_clckMicrosoft ClarityStatisticsUser identifier and preferences for Clarity1 year
_clskMicrosoft ClarityStatisticsConnects page views within a single session1 day
CLID, ANONCHK, MUID, SMMicrosoft (clarity.ms)StatisticsTechnical identifiers of the Clarity service1 day – 1 year
sbjs_first, sbjs_current, sbjs_first_add, sbjs_current_add, sbjs_udata, sbjs_session, sbjs_migrationsMDExpert Clinic (first party, WooCommerce Sourcebuster)StatisticsRecords the source of the visit (referrer, campaign) and the sessionsession – 30 days
Elfsight / Instagram cookies (e.g. ig_did, csrftoken, mid)Elfsight PTE. LTD.; Meta Platforms Ireland Ltd.Marketing / social mediaDisplay of the Instagram feed and the provider's own technical and statistical purposesas per the provider's notice, up to 2 years

Visitors may also block or delete cookies in their browser settings, and may opt out of Google Analytics measurement using Google's browser add-on. The cookie settings can be reopened at any time via the “Cookie settings” link in the footer.

6. Processors and recipients

The Controller uses the processors listed below, who process personal data exclusively on the written instructions of the Controller, under a processing agreement (Article 28 GDPR), and who may not use that data for their own purposes.

ProcessorActivityProcessing concerned
BlazeArts Kft. (Forpsi.hu)
39 Thaly Kálmán Street, 1096 Budapest
Reg. no. 01-09-389087 · https://www.forpsi.hu
Hosting of the Website, technical storage and transmission of form data5.1, 5.3
MiniCRM Zrt.
13–14 Madách Imre Road, 1075 Budapest
https://www.minicrm.hu
Customer relationship management (CRM) system and newsletter service: receiving and storing data submitted through the forms, sending newsletters and producing statistics5.1, 5.3, 5.4
Medio MedTech Zrt. (MyMedio online booking system)
2 Lechner Ödön fasor, 7th floor 13, 1095 Budapest
Reg. no. 01-10-141172 · info@mymedio.hu · https://mymedio.hu
Operation of the online appointment booking interface, sending confirmation and reminder messages5.2
Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Ireland
Google Fonts – serving the typefaces of the Website; Google Analytics 4 – website analyticsthe Website as a whole, 5.10
Meta Platforms Ireland Limited
Merrion Road, Dublin 4, D04 X2K5, Ireland
Operation of the Clinic's Facebook and Instagram pages5.5
Medio MedTech Zrt. (Medio practice management system)
2 Lechner Ödön fasor, 7th floor 13, 1095 Budapest
Electronic maintenance of medical records, EESZT connection5.6
KBOSS.hu Kft. (Számlázz.hu)
7 Záhony Street, 1031 Budapest
https://www.szamlazz.hu
Issuing invoices5.7
Patikapartner Kft.
12–14 Könyves Kálmán Boulevard, 1097 Budapest (Lurdy House)
https://patikapartner.hu
Bookkeeping and tax administration5.7
Microsoft Ireland Operations Ltd. (Microsoft 365)
One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
E-mail and document management; Microsoft Clarity – analysis of visitor behaviour5.1, 5.3, 5.10
Elfsight PTE. LTD.
60 Paya Lebar Road, #07-54 Paya Lebar Square, Singapore 409051 · https://elfsight.com
Display of the Instagram feed widget on the Website (only with marketing consent)5.10

Beyond the above, the Controller discloses personal data to third parties solely on the basis of a statutory obligation (for example upon the request of an authority, a court, the tax authority or the EESZT). Physicians and healthcare professionals involved in care at the Clinic who are not employees of the Controller access patient data on behalf of the Controller, under a contract for professional collaboration concluded with the Clinic and subject to an obligation of professional secrecy.

7. Transfers to third countries

The Controller processes data primarily within the European Economic Area (EEA). However, when using Google services (Google Fonts, Google Analytics), the Meta social media pages and Instagram content, and Microsoft 365 and Microsoft Clarity, personal data may also be transferred to the United States. The legal basis for such transfers is the adequacy decision of the European Commission on the EU–U.S. Data Privacy Framework (Article 45 GDPR) – Google LLC, Meta Platforms, Inc. and Microsoft Corporation being certified participants of the Framework – supplemented by the standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR). The provider of the Instagram feed widget, Elfsight PTE. LTD., operates in Singapore; transfers to it – which take place only with the data subject's marketing consent – are based on the standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR). Data subjects may request a copy of the appropriate safeguards from the Controller.

8. Data security

In accordance with Article 32 GDPR, the Controller applies technical and organisational measures proportionate to the risks, in particular: the Website and its forms operate over an encrypted (HTTPS/TLS) connection; health data is accessible only to authorised staff bound by professional secrecy, using individual identifiers and passwords; access within the systems is logged; paper documentation is stored in a lockable location; regular backups are made; staff receive data protection training; and processing agreements are concluded with processors. In the event of a personal data breach, the Controller acts in accordance with Articles 33–34 GDPR and, in the case of a high-risk breach, also informs the data subjects.

9. Rights of data subjects

Data subjects may exercise the following rights vis-à-vis the Controller, using the contact details given in Section 2 or through the Data Protection Officer:

9.1. Exercising these rights

The Controller complies with a request without undue delay and in any event within one month of its receipt, or informs the data subject of the reasons for non-compliance; this period may be extended by a further two months taking into account the complexity of the request. Information and action are provided free of charge, unless the request is manifestly unfounded or excessive by reason of its repetitive character. In the case of requests concerning health data, and having regard to the sensitivity of that data, the Controller verifies the identity of the data subject by appropriate means before complying.

10. Remedies

If a data subject considers that the processing of their personal data infringes the law, we ask that they first contact the Controller or its Data Protection Officer so that the matter may be resolved directly. In addition, the data subject may:

11. Amendment of this notice

The Controller reserves the right to amend this notice unilaterally in the event of changes to the legal environment, to the services used or to its processing practices. The notice in force at any given time is available on the Website; in the event of a material change, the Controller informs data subjects by a notice published on the Website and informs newsletter subscribers by e-mail as well. Earlier versions of the notice may be requested from the Controller.

MDExpert Clinic Kft. · 5 Rétköz Street, 1118 Budapest, Hungary · clinic@mdexpert.hu · +36 70 676 5885
English translation of the Hungarian original; in the event of any discrepancy, the Hungarian text prevails.