How UDY Digital, operator of DoctorVi, processes personal data of patients and visitors. Prepared under the EU General Data Protection Regulation (GDPR) and, where applicable, Turkey's Personal Data Protection Law (KVKK).
Updated: 2026-04-27
UDY Digital
Rissenerstr. 42, 22880 Wedel, Germany
Umut Deniz Yorulmaz
[email protected]
A statutory Data Protection Officer is not legally required.
Account data: name, email, password (hashed), preferred language. Legal basis: contract performance, Art. 6 (1) (b) GDPR.
Treatment requests & messages: the description you write (which can include health information), the city/budget/date you provide, and any messages or video calls between you and clinics. Health data is special category data under Art. 9 GDPR — we process it on the basis of your explicit consent (Art. 9 (2) (a)) given at the moment you submit a request. You can withdraw consent and have your data deleted at any time.
Reviews & experience reports: if you choose to publish a review, the content and the displayed name are public.
Usage & log data: IP, timestamp, user agent, URL — for security and abuse detection (Art. 6 (1) (f)).
Marketing: only with opt-in consent (Art. 6 (1) (a)). You can unsubscribe in every email.
When you publish an open treatment request, clinics matching your criteria can read it and send you offers. They become independent controllers for the data they receive at that point. We share with you which clinic received your data and link to that clinic's own privacy notice when it contacts you.
A patient's direct contact information is shared with a specific clinic only after you accept that clinic's offer or actively start a chat.
| Service | Purpose | Region |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage | EU (Frankfurt) |
| Resend, Inc. | Transactional & marketing email | EU / US (SCC) |
| Coolify (self-hosted) | Application hosting | EU (Germany) |
Transfers to third countries (e.g. USA) only happen with appropriate safeguards — Standard Contractual Clauses and supplementary technical measures.
Send requests to [email protected]. You may also lodge a complaint with a supervisory authority — in Schleswig-Holstein: ULD.
DoctorVi uses automated systems to match patient requests with clinics whose specialty, city and price range fit the request, and to draft suggested replies for clinics. These systems do not take final decisions that produce legal effects on you. Match suggestions are non-binding, and any reply you receive from a clinic is reviewed and sent by a human staff member of that clinic.
Where AI is used to draft text, the relevant content is clearly marked. You may at any time request a human review (Art. 22 (3) GDPR) by writing to [email protected].
Technical and organisational measures (TOMs) include:
We notify the competent supervisory authority within 72 hours of becoming aware of a personal-data breach that is likely to result in a risk to the rights and freedoms of natural persons (Art. 33 GDPR). If the breach is likely to result in a high risk to your rights and freedoms, we notify you directly without undue delay (Art. 34 GDPR).
DoctorVi is intended for users 18+ years of age. Patients under 18 must be represented by a parent or legal guardian.