GDPR Compliance Statement

Last Updated: 8/24/2026

Version: 1.0

Our Commitment to GDPR

Doktu is fully committed to compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679. As a healthcare platform processing special category data under Article 9, we implement the highest standards of data protection.

We are registered with the French Data Protection Authority (CNIL) and comply with all EU data protection regulations.

Legal Framework

GDPR Article 9 - Processing of Health Data

We process health data under the following legal bases:

  • Article 9(2)(h): Healthcare provision and management
  • Article 9(2)(a): Explicit consent where required
  • Article 9(2)(i): Public health interests

GDPR Article 6 - Lawfulness of Processing

General data processing is based on:

  • Article 6(1)(b): Contract performance
  • Article 6(1)(c): Legal obligations
  • Article 6(1)(a): Consent for marketing

Data Protection Measures

Technical Measures

  • ✓ End-to-end encryption
  • ✓ AES-256 data encryption
  • ✓ Secure access controls
  • ✓ Regular security audits

Organizational Measures

  • ✓ Staff training programs
  • ✓ Data protection policies
  • ✓ Access restrictions
  • ✓ Incident response plans

Data Protection Impact Assessment (DPIA)

We have conducted a comprehensive DPIA for our telemedicine platform, addressing:

  • Processing of health data at large scale
  • Use of video consultation technology
  • Cross-border data transfers within EU
  • Integration with third-party services (Zoom, Stripe)
  • Long-term storage of medical records

Data Subject Rights

We fully support all rights granted under GDPR:

Right to Access (Article 15)

Request copies of your personal data

Right to Rectification (Article 16)

Correct inaccurate personal data

Right to Erasure (Article 17)

Request deletion of your data

Right to Restriction (Article 18)

Limit processing of your data

Right to Portability (Article 20)

Transfer data to another provider

Right to Object (Article 21)

Object to certain processing

Right to Withdraw Consent (Article 7)

Withdraw consent at any time

Right to Complain (Article 77)

Lodge complaint with supervisory authority

Data Processing Activities

ActivityLegal BasisRetention
Medical consultationsArticle 9(2)(h)10 years
Payment processingArticle 6(1)(b)7 years
Account managementArticle 6(1)(b)Active + 3 years
Marketing communicationsArticle 6(1)(a)Until withdrawn

Data Breach Response

Our incident response plan ensures compliance with GDPR breach notification requirements:

  • Supervisory authority notification within 72 hours (Article 33)
  • Data subject notification for high-risk breaches (Article 34)
  • Comprehensive breach documentation and remediation
  • Regular security testing and vulnerability assessments

Third-Party Processors

All our data processors are GDPR-compliant and bound by data processing agreements:

Supabase: Supabase - Database hosting (EU servers)
Zoom: Zoom - Video consultations (GDPR-compliant, EU data region)
Stripe: Stripe - Payment processing (PCI DSS Level 1)
SendGrid: processors.sendgrid

International Data Transfers

All data processing occurs within the European Economic Area (EEA). Any transfers outside the EEA are protected by:

  • EU Commission adequacy decisions
  • Standard Contractual Clauses (SCCs)
  • Binding Corporate Rules (BCRs)

Contact Our Data Protection Officer

For any GDPR-related inquiries or to exercise your data protection rights:

Data Protection Officer: Doktu Limited

Email: doktu@doktu.co

Phone: +44 7448 888 747

Address: 24 St. Marys Close, Epsom, Surrey, KT17 2BA, United Kingdom

Response time: We aim to respond to all requests within 30 days as required by GDPR.

Supervisory Authorities

You have the right to lodge a complaint with your national data protection authority:

United Kingdom (Lead Authority):

Information Commissioner's Office (ICO)

ico.org.uk

For Bosnia and Herzegovina, contact the Agency for Personal Data Protection (AZLP).

Compliance Certifications

GDPR Compliant since May 25, 2018
ISO 27001 Information Security (In Progress)
HIPAA Compliant Infrastructure
ePrivacy Directive Compliant

This GDPR Compliance Statement is regularly reviewed and updated to ensure ongoing compliance with evolving data protection regulations.