Effective date: 7 May 2026
Website: Osteopathy Syros
Operated by: Marcin Wojtaszek – Osteopathy Syros
Service: Mobile osteopathic care in Syros, Cyclades, Greece
This Privacy Policy explains how Osteopathy Syros collects, uses, stores and protects personal data, including health information, when you use this website, contact us, book an appointment, complete a patient form or receive osteopathic care.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), applicable Greek data-protection law, including Law 4624/2019 where relevant, and applicable professional, legal and insurance obligations.
1. Who we are
Osteopathy Syros is operated by Marcin Wojtaszek, providing mobile osteopathic care in Syros, Greece.
For data-protection enquiries, you can contact us at:
Email: info@osteopathysyros.com
Phone: +30 697 822 7043
Location: Kini, Syros, Cyclades, Greece
For the purposes of GDPR, Osteopathy Syros is the data controller for the personal data we collect and use in connection with our website, bookings, patient forms, clinical records and osteopathic services.
2. What personal data we collect
We collect different types of personal data depending on how you interact with us.
a) Contact and enquiry information
When you contact us through the website, by email, phone, social media or another communication method, we may collect:
- your name;
- email address;
- phone number;
- message content;
- any other information you choose to provide.
We use this information to respond to your enquiry and communicate with you.
b) Appointment booking information
Appointments are managed through Cliniko, our third-party booking and practice-management system.
When you book an appointment, we may collect:
- your first name and surname;
- date of birth;
- email address;
- phone number;
- appointment type;
- appointment date and time;
- practitioner name;
- appointment address for mobile visits;
- booking notes or other information you provide;
- acceptance of terms, cancellation policy and privacy information;
- marketing preference, where you choose to provide it.
This information is used to arrange, confirm and manage your appointment.
c) Mobile appointment and home-visit information
Because Osteopathy Syros provides mobile appointments, we may collect information relevant to the safety and practicality of a home visit, including:
- address where treatment will take place;
- access information, such as parking, stairs, lift access, gate codes, building entrance details or directions;
- whether there is suitable space for a portable treatment couch;
- whether pets are present at the property;
- any other information that may affect access, safety or treatment setup.
We collect this information to help provide a safe and appropriate mobile osteopathy service.
d) Patient intake forms and health information
Before or during an appointment, you may be asked to complete a patient intake form. We may collect and process health information including:
- current symptoms and main reason for appointment;
- location, duration and nature of symptoms;
- pain or symptom severity;
- medical history;
- previous surgery, fractures, accidents, falls or trauma;
- medication;
- allergies;
- pregnancy or post-partum information, where relevant;
- red flag or safety-screening information;
- GP, doctor or healthcare-provider details, where provided;
- emergency contact details;
- relevant lifestyle, work, activity or health information;
- any other information you provide that is relevant to safe osteopathic care.
Health information is special-category personal data under GDPR. We only collect health information that is relevant to preparing for, providing, documenting and safely managing your osteopathic care.
e) Clinical records
If you attend an appointment, we will create and maintain clinical records. These may include:
- presenting complaint and case history;
- medical history and systems review;
- examination findings;
- clinical reasoning and working diagnosis;
- risk screening, precautions and contraindications;
- consent discussions and consent records;
- treatment provided;
- advice, exercises and management plans;
- referrals or recommendations for onward care;
- follow-up plans;
- communications about your clinical care;
- records of who was present during the appointment, where relevant;
- location of the appointment where care is provided outside a clinic setting.
Clinical records are kept to support safe care, professional accountability, continuity of care, insurance requirements and legal or regulatory obligations.
f) Payment, invoice and administrative information
Where applicable, we may collect information necessary for payment, receipts, invoices, accounting and tax purposes, including:
- payment status;
- invoice or receipt details;
- billing information;
- financial records required for accounting or tax compliance.
We do not intentionally collect payment-card details through this website unless a secure third-party payment provider is used.
g) Website technical information
When you visit this website, certain technical information may be collected automatically, including:
- IP address;
- browser type;
- device type;
- operating system;
- pages visited;
- date and time of visit;
- referring website;
- cookie information.
This information may be collected through cookies, website hosting systems, analytics tools or embedded third-party services.
h) Comments, media and embedded content
If comments are enabled on the website and you leave a comment, we may collect the data shown in the comments form, your IP address and browser user agent string to help detect spam.
If you upload images to the website, you should avoid uploading images with embedded location data, such as EXIF GPS data.
Pages on this website may include embedded content, such as maps, videos or external links. Embedded content from other websites behaves as if you visited those websites directly. Those websites may collect data about you, use cookies or track your interaction with their content.
3. How we use your personal data
We may use personal data for the following purposes:
- responding to enquiries;
- arranging and managing appointments;
- confirming, changing or cancelling appointments;
- sending appointment reminders or appointment-related messages;
- preparing for your appointment;
- providing osteopathic assessment, treatment, advice and follow-up care;
- maintaining clinical records;
- documenting consent, treatment, advice and clinical decisions;
- managing patient safety, including red flag screening and referrals where necessary;
- contacting your GP, another healthcare provider or emergency services where clinically necessary and lawful;
- managing payments, receipts, accounting and administration;
- complying with legal, professional, insurance and regulatory obligations;
- improving website functionality and security;
- managing cookies and website analytics where permitted;
- sending marketing messages only where you have given consent.
We do not sell personal data.
4. Legal basis for processing
We process personal data only where we have a lawful basis under GDPR.
Depending on the situation, we may rely on one or more of the following legal bases:
a) Consent
We may rely on consent where you:
- submit an enquiry;
- complete optional parts of a form;
- accept non-essential cookies;
- choose to receive marketing messages;
- provide explicit consent for certain health information where appropriate.
You can withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
b) Performance of a contract
We may process personal data where necessary to arrange, manage and provide an appointment or service you have requested.
This includes booking information, contact details, appointment management and service-related communication.
c) Legal obligations
We may process personal data where necessary to comply with legal obligations, including accounting, tax, insurance, clinical record keeping, regulatory or other legal requirements.
d) Legitimate interests
We may process personal data where necessary for legitimate interests, provided your rights and freedoms do not override those interests. This may include:
- responding to enquiries;
- managing the website;
- maintaining website security;
- managing appointment administration;
- protecting our legal position;
- maintaining accurate business and clinical records;
- managing clinical safety and continuity of care.
e) Vital interests
In rare situations, we may process or share personal data where necessary to protect your vital interests or the vital interests of another person, for example in a medical emergency.
f) Special-category health data
Health information is special-category personal data under GDPR. Where we process health information, we do so only where an Article 9 GDPR condition applies, such as:
- your explicit consent, where appropriate;
- processing necessary for the provision of health-related care or treatment, where applicable;
- processing necessary to protect vital interests in an emergency;
- processing necessary for the establishment, exercise or defence of legal claims;
- processing required or permitted by applicable legal, professional or insurance obligations.
5. Cliniko and appointment-management systems
We use Cliniko as our booking, patient form and practice-management system. Cliniko may be used to process:
- appointment bookings;
- patient contact details;
- appointment forms;
- clinical records;
- appointment reminders and communications;
- administrative records.
Cliniko is operated by Red Guava Pty Ltd. When Cliniko processes patient or appointment information on behalf of Osteopathy Syros, it acts as a data processor.
According to Cliniko, European account data is stored in Ireland. Cliniko also states that data is encrypted in transit and at rest, and backed up daily. Cliniko’s EU Data Processing Addendum includes Standard Contractual Clauses for relevant international transfers.
You can read Cliniko’s own privacy and security information on Cliniko’s website.
6. Data sharing
We only share personal data where necessary and lawful.
We may share personal data with:
- Cliniko, our booking and practice-management platform;
- website hosting providers;
- IT service providers;
- email, communication or reminder systems;
- accounting, tax or administrative service providers;
- payment providers, where relevant;
- professional advisers, insurers or legal advisers;
- a GP, doctor, healthcare provider, specialist or emergency service where clinically necessary and lawful;
- regulatory, public or legal authorities where required by law;
- spam detection or security services where used on the website.
We do not sell personal data to third parties.
Where service providers process personal data on our behalf, we take reasonable steps to ensure that they process the data securely and in accordance with applicable data-protection requirements.
7. International data transfers
Some service providers may be located outside Greece or outside the European Economic Area.
Where personal data is transferred outside the European Economic Area, we take reasonable steps to ensure that appropriate safeguards are in place. These may include:
- processing within the European Economic Area where available;
- adequacy decisions;
- Standard Contractual Clauses;
- data-processing agreements;
- technical and organisational security measures.
Cliniko is operated by an Australian company, Red Guava Pty Ltd, and may use sub-processors in different countries. Cliniko provides an EU Data Processing Addendum and Standard Contractual Clauses for relevant international transfers.
8. Data retention
We keep personal data only for as long as necessary for the purpose for which it was collected, including clinical, legal, professional, insurance, accounting and regulatory requirements.
Retention periods may vary depending on the type of information.
Enquiry data
General enquiry data is kept only for as long as necessary to respond to the enquiry and manage any related communication, unless the enquiry leads to an appointment or clinical relationship.
Booking and appointment data
Booking and appointment data is retained for as long as necessary to manage appointments, maintain accurate records and meet administrative, legal, professional or insurance requirements.
Clinical records
Clinical records are retained for the period required or recommended for clinical, professional, insurance and legal purposes.
Where a specific retention period is not stated, we determine the retention period by considering:
- applicable Greek legal requirements;
- professional guidance;
- insurance requirements;
- limitation periods for legal claims;
- the need to maintain safe and accurate clinical records;
- the nature of the information and the purpose for which it was collected.
Financial and accounting records
Financial, invoice, receipt and accounting records are retained for the period required by applicable tax, accounting and legal obligations.
Marketing data
Marketing contact details and marketing consent records are kept until consent is withdrawn or the information is no longer required. You can withdraw marketing consent at any time.
Website data and cookies
Website technical data and cookie-related information are retained according to our Cookie Policy and the settings of the relevant website tools or providers.
9. Security
We take appropriate technical and organisational measures to protect personal and health information.
These measures may include:
- secure electronic systems;
- restricted access to patient records;
- password-protected accounts;
- use of reputable service providers;
- secure appointment and clinical-record systems;
- reasonable steps to protect against unauthorised access, loss, misuse, alteration or disclosure.
No online system can be guaranteed to be completely secure, but we take reasonable steps to protect the personal data we process.
10. Confidentiality
We respect patient confidentiality.
Personal and health information is only accessed or shared where necessary for appointment management, clinical care, administration, safety, legal compliance, insurance or professional purposes.
We will not share your health information with another healthcare provider, GP, family member or third party unless:
- you have given consent;
- it is clinically necessary and lawful;
- it is necessary to protect your vital interests or another person’s vital interests;
- it is required by law;
- it is necessary for legal, insurance or professional purposes.
11. Marketing communications
We will only send marketing messages if you have chosen to receive them.
Marketing consent is separate from appointment and clinical communication.
You can withdraw consent to marketing at any time by contacting us or using any unsubscribe option provided.
Withdrawing marketing consent will not affect appointment-related or clinically necessary communications.
12. Appointment and clinical communications
We may contact you about:
- appointment confirmations;
- appointment reminders;
- appointment changes or cancellations;
- patient forms;
- clinical follow-up;
- safety-related information;
- treatment advice or management plans;
- administrative matters related to your care.
These communications are part of appointment management and clinical care and are separate from marketing.
13. Emergency information
Patient forms and website messages are not monitored as emergency services.
If you are experiencing symptoms that may require urgent medical attention, such as chest pain, severe shortness of breath, sudden weakness, loss of bladder or bowel control, numbness around the groin or saddle area, fainting, sudden severe headache, speech difficulty, facial drooping or other serious symptoms, you should seek urgent medical help and not wait for an osteopathy appointment or a response from this website.
14. Children and minors
Where a patient is under 18, we may collect and process personal data about the child and their parent, guardian or responsible adult.
Where appropriate, consent for assessment and treatment must be provided by a person with parental responsibility or legal authority. We may also record who attended the appointment and who provided consent.
15. Your rights
Under GDPR, you have rights in relation to your personal data. These may include the right to:
- access your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of personal data, where legally permitted;
- restrict processing;
- object to processing;
- request data portability, where applicable;
- withdraw consent where processing is based on consent;
- complain to a supervisory authority.
Some rights may be limited where we are required to keep information for clinical, legal, insurance, professional or regulatory reasons.
For example, if you withdraw consent to treatment or request deletion of records, we may still need to retain clinical records where this is required or justified for legal, professional, insurance or clinical safety reasons.
To exercise your rights, please contact:
Email: info@osteopathysyros.com
We may need to verify your identity before responding to a data request.
16. Complaints
If you are concerned about how your personal data is handled, please contact us first so we can try to resolve the issue.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority, the supervisory authority for data protection in Greece.
17. Cookies
This website may use cookies and similar technologies to support website functionality, security, analytics or user experience.
Non-essential cookies, such as analytics or marketing cookies, are only used where consent is required and has been given.
For more information, please see our Cookie Policy.
18. Third-party links
This website may contain links to third-party websites, including booking systems, maps, social media platforms or other external services.
We are not responsible for the privacy practices of third-party websites. You should read the privacy policies of any external websites or services you use.
19. Automated decision-making
We do not use your personal data for automated decision-making that produces legal or similarly significant effects.
20. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, website, booking systems, legal requirements or data-processing practices.
The updated version will be published on this page with a new effective date.
21. Contact
If you have any questions about this Privacy Policy or how your personal data is handled, please contact:
Osteopathy Syros
Marcin Wojtaszek
Email: info@osteopathysyros.com
Phone: +30 697 822 7043
Location: Kini, Syros, Cyclades, Greece
