Last updated: December 7, 2025
The data controller responsible for your personal data is:
AfaTech GmbH
Brucknerstraße 78
8010 Graz, Austria
Firmenbuchnummer: FN 633728d
Email: info@afatechco.com
Phone: +43 680 336 8742
For data protection inquiries, please contact us at info@afatechco.com
⚠️ Important: Health-related data is considered special category data under GDPR Article 9 and receives enhanced protection. We process this data based on your explicit consent and for the provision of healthcare services.
We process your data under the following legal bases (GDPR Article 6):
Processing necessary to provide therapy marketplace services, bookings, and payments.
Processing of health-related data, marketing communications, and optional features.
Tax compliance, financial record keeping, and regulatory requirements.
Fraud prevention, security, platform improvement, and analytics.
We share your data only with the following categories of recipients:
| Provider | Purpose | Data Location |
|---|---|---|
| Stripe | Payment processing | EU (GDPR compliant) |
| Microsoft Clarity | Session replay, heatmaps, behavioral analytics | US (SCCs in place) |
| Google Analytics | Usage analytics | US (SCCs in place) |
| [HOSTING PROVIDER] | Server hosting & database | [TO BE SPECIFIED] |
| [EMAIL PROVIDER] | Transactional emails | [TO BE SPECIFIED] |
We may disclose your data when required by law, court order, or regulatory authority.
In case of merger, acquisition, or sale of assets, your data may be transferred to the new entity (you will be notified in advance).
Your data is primarily stored and processed within the European Economic Area (EEA). When we transfer data outside the EEA, we ensure adequate protection through:
We retain your data for different periods based on data type and legal requirements:
| Data Type | Retention Period |
|---|---|
| Account data (active accounts) | Until account deletion requested |
| Account data (inactive accounts) | 3 years after last activity, then deleted |
| Session & health data | 7 years (healthcare record requirements) |
| Financial records | 10 years (Austrian tax law requirement) |
| Marketing consent | Until withdrawn, max 3 years |
| Technical logs | 90 days |
You have the following rights regarding your personal data:
Request a copy of all data we hold about you
Correct inaccurate or incomplete data
Request deletion of your data ("right to be forgotten")
Receive your data in machine-readable format
Limit how we use your data
Object to data processing for specific purposes
Revoke consent at any time
Lodge complaint with supervisory authority
How to Exercise Your Rights:
We implement industry-standard security measures to protect your data:
Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that a child under 16 has provided us with personal data, we will delete it immediately.
If you are a parent or guardian and believe your child has provided personal data, please contact us at info@afatechco.com.
We use cookies and similar technologies. For detailed information, please see our Cookie Policy.
We partner with Microsoft Clarity and Microsoft Advertising to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve and market our products/services. Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of products/services and online activity. Additionally, we use this information for site optimization, fraud/security purposes, and advertising.
For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.
We use Google Analytics to analyze website traffic and usage patterns. This service collects information about how visitors use our site, including pages visited, time spent on pages, and referral sources. This data helps us understand user behavior and improve our platform.
For more information about how Google collects and uses your data, visit the Google Privacy Policy.
We may update this Privacy Policy from time to time. Material changes will be notified via email or prominent notice on our platform. Continued use of our services after changes constitutes acceptance of the updated policy.
You have the right to lodge a complaint with the Austrian Data Protection Authority:
Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Wien, Austria
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: www.dsb.gv.at
For any privacy-related questions or to exercise your rights, contact us:
Email: info@afatechco.com
Phone: +43-664-4111294
Address: AfaTech GmbH, Brucknerstraße 78, 8010 Graz, Austria
Document Version: 1.0
Effective Date: December 7, 2025
Governing Law: Austrian law and EU GDPR