GDPR Compliance Statement
Last Updated: 8/24/2026
Version: 1.0
Our Commitment to GDPR
Doktu is fully committed to compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679. As a healthcare platform processing special category data under Article 9, we implement the highest standards of data protection.
We are registered with the French Data Protection Authority (CNIL) and comply with all EU data protection regulations.
Legal Framework
GDPR Article 9 - Processing of Health Data
We process health data under the following legal bases:
- Article 9(2)(h): Healthcare provision and management
- Article 9(2)(a): Explicit consent where required
- Article 9(2)(i): Public health interests
GDPR Article 6 - Lawfulness of Processing
General data processing is based on:
- Article 6(1)(b): Contract performance
- Article 6(1)(c): Legal obligations
- Article 6(1)(a): Consent for marketing
Data Protection Measures
Technical Measures
- ✓ End-to-end encryption
- ✓ AES-256 data encryption
- ✓ Secure access controls
- ✓ Regular security audits
Organizational Measures
- ✓ Staff training programs
- ✓ Data protection policies
- ✓ Access restrictions
- ✓ Incident response plans
Data Protection Impact Assessment (DPIA)
We have conducted a comprehensive DPIA for our telemedicine platform, addressing:
- Processing of health data at large scale
- Use of video consultation technology
- Cross-border data transfers within EU
- Integration with third-party services (Zoom, Stripe)
- Long-term storage of medical records
Data Subject Rights
We fully support all rights granted under GDPR:
Right to Access (Article 15)
Request copies of your personal data
Right to Rectification (Article 16)
Correct inaccurate personal data
Right to Erasure (Article 17)
Request deletion of your data
Right to Restriction (Article 18)
Limit processing of your data
Right to Portability (Article 20)
Transfer data to another provider
Right to Object (Article 21)
Object to certain processing
Right to Withdraw Consent (Article 7)
Withdraw consent at any time
Right to Complain (Article 77)
Lodge complaint with supervisory authority
Data Processing Activities
| Activity | Legal Basis | Retention |
|---|---|---|
| Medical consultations | Article 9(2)(h) | 10 years |
| Payment processing | Article 6(1)(b) | 7 years |
| Account management | Article 6(1)(b) | Active + 3 years |
| Marketing communications | Article 6(1)(a) | Until withdrawn |
Data Breach Response
Our incident response plan ensures compliance with GDPR breach notification requirements:
- Supervisory authority notification within 72 hours (Article 33)
- Data subject notification for high-risk breaches (Article 34)
- Comprehensive breach documentation and remediation
- Regular security testing and vulnerability assessments
Third-Party Processors
All our data processors are GDPR-compliant and bound by data processing agreements:
International Data Transfers
All data processing occurs within the European Economic Area (EEA). Any transfers outside the EEA are protected by:
- EU Commission adequacy decisions
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules (BCRs)
Contact Our Data Protection Officer
For any GDPR-related inquiries or to exercise your data protection rights:
Data Protection Officer: Doktu Limited
Email: doktu@doktu.co
Phone: +44 7448 888 747
Address: 24 St. Marys Close, Epsom, Surrey, KT17 2BA, United Kingdom
Response time: We aim to respond to all requests within 30 days as required by GDPR.
Supervisory Authorities
You have the right to lodge a complaint with your national data protection authority:
United Kingdom (Lead Authority):
Information Commissioner's Office (ICO)
ico.org.uk
For Bosnia and Herzegovina, contact the Agency for Personal Data Protection (AZLP).
Compliance Certifications
This GDPR Compliance Statement is regularly reviewed and updated to ensure ongoing compliance with evolving data protection regulations.