TVARKA.HEALTH
Tvarka.health privacy policy
Effective 30 September 2026.
This policy applies to the public website and the service functions you use. Healthcare provisions apply when you use the corresponding service.
1. Who is responsible. Socialiniai algoritmai, UAB, company code 304068578, M. Valančiaus g. 1A-21, LT-03155 Vilnius (Operator), controls data for the public website, platform accounts, account administration, marketing and its own security. Medicinos stebuklas, UAB, company code 124092339, Saltoniškių g. 29, LT-08106 Vilnius (Provider), controls its patients’ healthcare data and medical records. If you choose another participating Provider, its details appear in the order. The Operator acts as the Provider’s processor when handling health data on its instructions. This policy covers both activities and applies to the functions you use. For data protection and rights requests, email [email protected] or the Provider at [email protected]. We route requests to the responsible controller.
2. Sources of data. You or your representative provide data when browsing, registering, ordering a service, giving information to a doctor or contacting us. The Provider also obtains data from e-sveikata, treating professionals, laboratories and other institutions entitled to supply them. Identity, signing and payment providers supply transaction confirmations. Public professional-directory information comes from VASPVT and other public professional sources identified on the page, the professionals themselves and their institutions.
3. Accounts, identity and orders. We process names, personal codes or other patient identifiers, dates of birth, contact details, language, representation details, identity-verification results, passkey public keys, and evidence of consents and orders. These support accounts, identity and representation checks and service ordering under GDPR Article 6(1)(b). Identification, accounting and documentation required by law rely on Article 6(1)(c). Required fields are marked; without information essential to identity or a particular service, we cannot provide that service. We do not receive the fingerprint or facial template used on your device to unlock a passkey. If a separate identity check uses an identity-document or facial image, the specific method’s privacy notice is supplied beforehand and separate consent is requested where required.
4. Healthcare. The Provider processes concerns, medical history, diagnoses, allergies, medicines, prescriptions and dispensing, vaccinations, tests, referrals, consultation and treatment information, patient-provided documents and photographs, and service-related messages. The extent depends on the service. Purposes include assessment, consultation, treatment selection and continuity, treatment safety, documentation and legal obligations. The grounds are GDPR Article 6(1)(b) or (c) and Article 9(2)(h), subject to professional confidentiality. Consent to receive a remote consultation is distinct from the legal basis for data processing. Acknowledging this policy is not blanket consent for every processing purpose.
5. E-sveikata exchanges. Through Tvarka.health, the Provider searches for and identifies patients in ESPBI IS, checks representation, obtains the history needed for care, and submits, corrects or cancels medical documents under the applicable rules. Information may include patient summaries, diagnoses, allergies, vaccinations, tests, prescriptions, dispensing, visits and referrals. Submissions may include E025, EREC01, E027 and other documents needed for the Provider’s services. Requests are made on behalf of the Provider, within its access permissions, and recorded in an audit log. Access begins after payment; payment itself does not grant unrestricted use of medical history. Information is obtained only for a specific service, continuity of care or a function you lawfully use. Mandatory exchanges rely on GDPR Article 6(1)(c) and Article 9(2)(h). The Ministry of Health controls ESPBI IS and the State Enterprise Centre of Registers is its main processor. Sick-leave data are submitted to Sodra under the relevant legal duties.
6. Optional functions. In “Your medicines” and repeat-consultation functions, current prescription and dispensing data support continuity of care and administration of your orders. Standalone health-data functions that are not necessary for care and have no other applicable legal basis require explicit consent under GDPR Article 6(1)(a) and Article 9(2)(a). You can withdraw it. Confidential health information is sent to an insurer or another recipient you choose under separate authorisation in the required form, except where legislation provides otherwise. An employer’s payment does not, by itself, give it access to diagnoses or medical records. Switching off an optional function leaves statutory retention duties for existing medical and accounting records intact.
7. Payments, support and security. Payment references, amounts, statuses, refunds and invoice data are processed to perform contracts and meet accounting duties. Stripe handles payment-card data; the platform uses payment references and confirmations. We handle enquiries and complaints to respond, uphold patient and consumer rights, and establish or defend claims. The grounds are GDPR Article 6(1)(b), (c) or (f); disputes involving health data also rely on Article 9(2)(f) or (h). Sign-in, activity and technical logs support access control and incident detection and investigation. The legitimate interests are protecting accounts, infrastructure and legal rights; processing is limited to what those purposes require.
8. Website, directory and messages. Browsing generates an IP address, request time, page URL, browser information and security logs. We process them under GDPR Article 6(1)(f), pursuing the legitimate interest of delivering and protecting the site. The public professional directory contains names, qualifications, licences, specialties and professional locations. It helps visitors find professionals and relies on the legitimate interests of the Operator and visitors. Professionals may request corrections and object to processing. Service-launch or marketing messages follow your choices and consent; each message provides a way to opt out. Essential service reminders and payment messages rely on the contract. Necessary cookies and local storage maintain the session, security and language. Analytics or advertising tools requiring consent are enabled only after it is obtained. Health-related search words are not linked to an account to build a marketing profile.
9. Recipients. Recipients include your chosen Provider, its authorised professionals, and instructed technology, hosting, communications, document-processing, identity and signing suppliers. Laboratories receive information needed for tests; pharmacies receive information required by law or your order. Stripe handles payments. Cloudflare Pages and Cloudflare Tunnel deliver and protect the public website, and Resend delivers messages. Using these suppliers for the public site does not itself include sending clinical data to them. Health-data recipients are selected under the Provider’s instructions and contract. Information is disclosed to public bodies where required. Processors are bound by confidentiality and data-protection terms.
10. Location and international transfers. The Provider’s clinical-data repositories are subject to an EEA-location requirement. Cloudflare and Resend may handle public-site and message data in the United States or other countries where they operate. Transfers outside the EEA rely on a valid adequacy decision where it covers the recipient, or European Commission standard contractual clauses and necessary supplementary measures. You can obtain information about a recipient, the transfer basis and a copy of the safeguards by emailing [email protected]. Supplier terms are available at cloudflare.com/cloudflare-customer-dpa/ and resend.com/legal/dpa.
11. Retention. Account information is held while the account is used; after closure, only data needed for a legal obligation, specific dispute or documented security investigation are retained. Outpatient medical histories are kept for 15 years after the patient stops attending; special records and statutory exceptions follow their own periods. Consultation material forming part of the history follows its retention, while temporary copies are removed after transfer and verification. Accounting records follow statutory periods, generally 10 years. General enquiries are kept for one year after resolution; marketing recipient data until withdrawal or the notification purpose ends. Unconfirmed email registrations are removed within 30 days. Ordinary technical logs are kept for up to 90 days; evidence of access to and changes in medical records is retained as needed for the relevant record’s traceability. Data needed for a dispute or incident are retained until final resolution and expiry of the applicable claims period. Deleting an account does not erase medical documents or ESPBI IS entries lawfully retained.
12. Automated processing. Text and documents may be structured, translated and summarised using automated tools. A doctor assesses the resulting drafts and decides on diagnoses, treatment and documents. Service terms, your answers and current treatment information support routing and repeat-order timing. If an automatic service-scope check rejects or incorrectly routes a request, you may ask platform support for human review. This does not change the instruction to call 112 in an emergency. Consultation audio and video are neither recorded nor transcribed.
13. Your rights. You may request access, copies, correction, deletion, restriction and, where applicable, portability. You may object to processing based on legitimate interests and opt out of direct marketing at any time. You may withdraw consent without affecting processing lawfully carried out beforehand. We respond within one month; any extension permitted by law and its reasons are notified within that month. Identity and representation checks are proportionate to the request. Medical-record corrections may follow a specific procedure. You may complain to the Lithuanian State Data Protection Inspectorate (vdai.lrv.lt) and seek a judicial remedy. We notify you of material policy changes before the relevant new processing begins.