Privacy Policy
This Privacy Policy describes the personal data that Iatropolis collects about you, the way we use and protect your personal data, and the choices you have about how we use that data.
We recognize that the protection of personal data is an ongoing responsibility and therefore, we will update and amend this Notice from time to time. Please visit our website from time to time to make sure you are aware of any changes.
1. What personal data do we collect about you?
The personal data we process and maintain about you include, but are not limited to:
- Health Data. We collect your personal and health data about medical services provided by our Group companies, or health data for medical services that were not provided by us, but reported to us, either by you or by third parties.
- Login details to electronic services, such as username, password.
- Contact Details. We collect your name, address and, in general, your contact details (including your email address and telephone number (landline or mobile), yours or your relatives.
- Invoicing details. We collect your information that is necessary for the payment of our services, such as your VAT number, bank card information, etc.
- Unique identification numbers. We collect your AMKA, passport number, tax identification number, driver's license number, or other identification number, issued by a competent government authority.
- Recorded phone calls. When we manage your appointments over the phone, we record our conversation so that we can keep your requests, clarifications and instructions from the two of us or what we have agreed upon.
- Online activity data through cookies. When you use our companies' digital services to make sure our website works properly or to help us improve our services, we may sometimes place a small piece of data known as a cookie on your computer or mobile device. A cookie is a text file that is stored by a web server on a computer or mobile device. The content of a cookie can only be retrieved or read by the cookie server. The text in a cookie often consists of identifiers, the IP address of your computer or mobile phone, site names, and certain numbers and characters. Cookies are unique to browsers or mobile apps you use and allow websites to store data such as your preferences. You can read more about cookies in our cookie settings when we ask you for your consent to use them.
- The companies of our Group undertake not to process personal data from underage persons, without first obtaining the consent of the person exercising parental responsibility of the child.
2. How do we use (process) your personal data?
We use your personal data for the following purposes:
- provision of health services (performance of medical procedures and paraclinical examinations, as well as hospitalization health care) and the management of your medical file for the health services provided by the companies of our Group: all the personal data included in your medical file, including your medical history, the results of medical examinations, doctors' opinions, medication, etc.
- The provision of electronic access services to your digital medical record through the Patient Portal.
- Improving the quality of our services.
- Our communication with you.
- The documentation of the conversation and the protection from errors (e.g. instructions given, what was agreed, etc.) during the telephone management of the appointments of the examinees at the Iatropolis branches.
- Our compliance with applicable tax laws, health laws, and our regulatory obligations.
- To comply with legal procedures and court decisions and to respond to requests from public and state authorities.
- To enforce and defend our legal rights and claims in order to protect our business, or that of our business partners, and in order to safeguard the rights, privacy, security or assets of our group companies or business partners, your own legal claims or rights, or those of others; to pursue the available remedial measures and to limit our damage.
3. Where do we collect your personal data from?
Your personal data is collected from a variety of sources, including:
- From you, when Iatropolis provides medical services to you or to a person accompanying you, when he/she is not able to provide them himself, when you fill in electronic forms or send an e-mail ("email"), in order to be informed or use our services.
- Automatically through the browser or mobile device you use to access our Website.
- From our third-party partner after you have given your consent (e.g. your insurance company).
- From your phone calls to us, sending emails, and your other communications with us.
- From our social media pages, other social media content, tools, and apps.
- From your login to the Patient Portal as a user.
4. Lawful basis for processing your personal data
- The processing of your personal data and/or your special categories of personal data is done for the provision of our services to you, which is based on:
- In the conclusion and execution of a contract or - at your request - in preparatory actions for the conclusion and execution of a contract.
- To our legal obligation, as a health service provider and for our compliance with national and/or European legislation (e.g. tax purposes).
- Safeguarding your vital interest.
- In our legal interest in establishing, exercising or supporting our legal claims (e.g. collection of our claims for the provision of our services) or of third parties if they have an overriding legal interest than yours.
- Your consent when the processing of your personal data is done for marketing and/or promotional purposes or other purposes for which we expressly ask for your consent.
5. Retention period of your personal data
- When we provide you with health services, we keep your personal data for 10 years after your last visit for diagnostic or treatment purposes (the minimum time set by the Code of Medical Ethics Law 3418/2005).
- Your personal data, which is necessary for the documentation of our financial transactions, is kept for 5 years from the issuance of the relevant documents.
- Recorded telephone calls are kept for 12 months.
- Your personal data collected with your consent, except for cookies, is kept for 5 years from the date of receipt of consent.
- When we are to comply with a legal or regulatory obligation, we retain your personal data, at least for as long as it is required by law to comply with that obligation.
6. Guarantees we take to protect your data
When you give us your personal data, we take steps to ensure that it is kept securely. In order to protect your personal data, we take physical, technical and organizational measures to protect it. We update and control the security technology we use, on an ongoing basis. We restrict access to your strictly necessary personal data and to only those of our employees who need to know your data in order to provide benefits or our services to you. In addition, we train our staff on the importance of confidentiality and maintaining the confidentiality and security of your personal data and we bind them with confidentiality agreements and confidentiality of the information they become aware of due to the provision of our services. Among other things, we have implemented the following technical and organizational measures and procedures to protect your personal data from any loss, alteration, unlawful processing or alteration:
- They are processed lawfully and fairly in a transparent manner in relation to the data subject.
- They are collected solely for specific and legitimate purposes.
- They are sufficient, related to the purpose for which we collect them and are limited to what is necessary.
- They are accurate and up-to-date.
- They are kept exclusively within the specified time frame and no longer.
- They are processed in such a way as to ensure their necessary protection.
In addition:
- Encryption, data pseudonymization.
- Detection and management of security breach incidents.
- Use of servers located in rooms with limited access and subject to regular checks.
- Use of computer information systems and programs installed in a way that minimizes the use of personal and/or user authentication data.
- Adoption of individual procedures for the retention of personal data and their secure deletion / destruction.
- Access to systems and databases on the "need-to-know" principle.
- Storage and retention of your personal data (both simple and special categories - sensitive) which is in printed form, in a special storage space, protected and secure, to which there is no access by unauthorized people.
7. When and how do we transfer your personal data to others?
Your personal data is collected and processed by the authorized employees of Iatropolis per service, for the sole purpose of providing our service. They are transmitted only to authorized third parties (processors), who are bound to maintain confidentiality and act in accordance with our instructions, when they are required to have access, in the context of the provision of these services (e.g. doctors for diagnostic purposes, external diagnostic laboratories for the performance or confirmation of specialized tests, Social Security Institutions, insurance companies with which you have contracted, insurance program management companies), competent control authorities of the Ministry of Health or the Ministry of Finance or when required by law (e.g. obligation to report cases of infectious diseases).
In every transfer, we always take every measure so that the data transmitted is always the minimum necessary and that the conditions for their lawful and fair and transparent processing are always met.
8. Your rights
You have the right to request access to your personal data, which we process. In addition, you have the following permissions:
- Right to rectification or deletion (under conditions) of your personal data.
- Right to restrict processing or object to the processing of your personal data.
- Right (subject to conditions) to receive your personal data so that you can use it anywhere else.
- Where we process your personal data based on your consent, you also have the right to withdraw your consent at any time, without this affecting the lawfulness of the processing for the period prior to the withdrawal of your consent.
To exercise your rights click here.
The provision of your personal data is necessary for the provision of our services to you, therefore, in case you refuse to provide them by you, we will not be able to provide you with our services.
9. How to contact us?
In order to exercise your rights regarding the processing of your personal data, you can send your request electronically to This email address is being protected from spambots. You need JavaScript enabled to view it. email or submit it in form to our Offices or send it to the address: Ethnikis Antistaseos 56, Chalandri PC 15231
We have appointed a Data Protection Officer (DPO) to our Group companies. If you believe that your personal data or rights are being violated, you can contact the DPO by sending an email to This email address is being protected from spambots. You need JavaScript enabled to view it. or by sending a confidential letter to:
Ethnikis Antistaseos 56, Chalandri PC 15231 to the attention of the Data Protection Officer.
If we do not respond satisfactorily to your questions, you have the right to lodge a complaint with the competent Greek independent authority, which is the Data Protection Authority (http://www.dpa./gr/en).
We encourage you to review our Privacy Policy at the Privacy and Data Protection Policy.
10. Release Information – Changes and Updates
This Update was last updated on [9.01.2024].
We reserve the right to modify and update this Notice, at any time, for any reason, without prior notice to you, other than by posting the updated Information on our website. We may periodically send emails to remind you of changes and updates to this Notice, but you should check our website frequently to be informed of current Privacy Policy.

