This policy explains which personal data are processed when you use the DocAgora website and platform, for what purposes, on what legal basis, for how long, who receives them and how you can exercise your rights. DocAgora is the trade name operated by OXIGÉNIO BOÉMIO LDA.
Data controller
The controller of your data is OXIGÉNIO BOÉMIO LDA, a private limited company (sociedade por quotas) with its registered office at Rua do Grilo n.º 14, 1.º Dto, 1950-145 Lisboa, Portugal, registered with the Commercial Registry Office (Conservatória do Registo Comercial) under the single registration and legal entity number 519319346. General contact: contact@docagora.pt.
Data protection officer
We have appointed a data protection officer (DPO), Jimmy Salloum Diallo, whom you can contact with any question about your data or to exercise your rights: jimmydiallo@docagora.pt.
Who this policy applies to
It applies to website visitors, to patients who create an account, and to healthcare professionals and members of their teams (front desk) who use the platform.
For accounts, search, the search assistant, appointment requests, reviews, professional verification and subscriptions, OXIGÉNIO BOÉMIO LDA decides how data are processed and is the controller.
When a professional records information about their patients on the platform to run their practice (patient records they create, consultation notes, attendance records), the professional or their clinic is the controller of those data. OXIGÉNIO BOÉMIO LDA processes them on the professional's behalf, as a processor, only to provide the service. Requests about those data should be addressed to the professional; we help them respond.
Data we process
We only process the data needed for the features you use:
Account: first name, last name, email address, phone number, language, optional photo, role on the platform (patient, professional, front desk) and a record of the consents given (date and version of the accepted texts). Your password is handled by the authentication service and is never stored in plain text.
Patient profile, if you fill it in: date of birth, gender, address, postcode, city, languages spoken, insurer and policy number, emergency contact.
Appointment requests and consultations: professional, service, date and time, request status, the reason or notes you write, cancellations, no-shows and attendance.
Search assistant: the messages you write, the conversation history, the search criteria inferred and the language. On the website, without an account, a random session identifier is stored in your browser.
Reviews: rating, comment and any public reply from the professional. Reviews are published with your first name and the initial of your last name, or without a name if you choose to remain anonymous.
Healthcare professionals: identity, specialty, professional order registration number, verification documents (for example the professional licence), practice address and its location on the map, opening hours, services and prices, languages, accepted insurers, description and photo, replies to reviews and activity statistics.
Professional subscriptions: tax number (NIF), company name, billing address, billing email, plan, payment history and invoices. Card details are entered directly on Stripe's secure page: we never receive them.
Teams and clinics: invitations, members, front desk assignments and the clinic activity log.
Support and contact: support requests and their messages; messages sent through the website contact form (name, email, optional phone number, subject and message), received by email.
Google Calendar, only if a professional connects it: title, description, start and end of the events in the chosen calendars, read to block busy time slots. Access tokens are stored encrypted.
Notifications: history of reminders and notifications (channel, status, date sent).
Technical data: IP address and connection data processed by the servers and the content delivery network for security; in the website assistant, an irreversible fingerprint of the IP address is used to limit abuse.
Health data
The reason for an appointment, the specialty you search for, the messages written in the assistant or the mere fact of booking with a healthcare professional may reveal information about your health. These data enjoy enhanced protection (Article 9 GDPR). We only process them with your explicit consent, given when you create your account, and only to provide the service. Consultation notes are written by the professional, under their responsibility, and are not visible to front desk staff.
Purposes and legal bases
Each processing operation relies on a legal basis under Article 6 GDPR:
Creating and managing your account, searching for professionals, sending and following appointment requests, cancelling, publishing reviews: performance of the contract (terms of use).
Processing health data linked to appointments and to the assistant: your explicit consent. You can withdraw it at any time by deleting your account or writing to the DPO; withdrawal prevents use of the booking features and does not affect processing already carried out.
Sending confirmations, reminders and notifications about your appointments by email and, if the professional enables them and you have accepted these channels, by SMS or WhatsApp: performance of the contract.
Answering in the search assistant: performance of the request you make when using the assistant and, on the website without an account, our legitimate interest in offering search in everyday language.
Verifying professionals and publishing their profiles in the directory: performance of the contract and legitimate interest in keeping a reliable directory.
Managing professionals' subscriptions, payments and invoices: performance of the contract and compliance with tax and accounting obligations.
Answering support and contact requests: performance of the contract or legitimate interest.
Ensuring security and preventing abuse and fraud (usage limits, technical logs): legitimate interest.
Sending marketing communications, if you agree to receive them: your consent, optional and revocable at any time.
Complying with legal obligations and defending our rights: legal obligation and legitimate interest.
AI search assistant
The search assistant, on the website and in the patient area, uses a service provided by OpenAI (United States). The text you write and the earlier messages of the conversation are sent to it to interpret your request and turn it into search criteria; your name, email and IP address are not sent. Conversations are stored on our servers for 12 months after the last message, to run the service, prevent abuse and improve answers.
Do not write health information you do not need in the assistant: specialty, city and language are enough. The classic search, with filters, does not use this service. The assistant gives no medical advice and makes no decision for you: an appointment always requires your click and the professional's acceptance. In an emergency, call 112.
Who receives the data
Your data are only accessible to those who need them. We do not sell personal data or use them for advertising.
The healthcare professional you send an appointment request to and, if they work in a clinic, the front desk staff managing their calendar: identity, contact details, request details and the patient profile data useful for the consultation.
The public: professional profiles and published reviews (first name and last-name initial of the author, or anonymous).
The DocAgora team, to the extent needed for support, professional verification and moderation. In the administration panel, patients appear pseudonymised in appointment lists.
Our processors, listed below, who act on our instructions.
Public authorities, where required by law.
Processors
We use the following providers, bound by confidentiality and data protection obligations:
Supabase: database, authentication and file storage. Data hosted in the European Union (Paris region, France).
OVH SAS: hosting of the application servers, in France.
Cloudflare: content delivery network and traffic protection for the website and the platform (United States, global network).
Twilio SendGrid: sending transactional emails and website contact form messages (United States).
Twilio: sending reminders by SMS and WhatsApp (United States).
Resend: scheduled sending of review request emails (United States).
OpenAI: search assistant, automatic translation of professionals' service descriptions and aggregated statistical analyses of professionals' activity (United States).
Stripe: payment of professionals' subscriptions (Stripe Payments Europe, Ireland, with transfers to Stripe, Inc., United States).
Moloni: invoicing software certified by the Portuguese Tax Authority, for subscription invoices (Portugal).
Google: reading calendars, only if a professional connects Google Calendar; map on the contact page, only after you accept it (United States).
OpenStreetMap Foundation: maps shown in search results and profiles, and locating practice addresses (United Kingdom).
Fonticons (Font Awesome): website icons, loaded from its network (United States).
Proton: email mailboxes for @docagora.pt addresses (Switzerland).
Sentry: detection of technical errors, with IP addresses, cookies and identifiers removed beforehand (United States).
Transfers outside the European Union
Some providers are established in the United States or may access data from there. These transfers rely on the European Commission's adequacy decision on the EU-US Data Privacy Framework, for certified providers, or on standard contractual clauses approved by the European Commission, together with any necessary supplementary measures. The United Kingdom and Switzerland benefit from adequacy decisions. You can obtain more information about these safeguards from the DPO.
Retention periods
We keep data only for as long as needed for the purpose for which they were collected:
Account and profile: as long as the account exists. When you delete your account, account data, profile, favourites, conversations, support requests, notifications and settings are erased immediately.
Unused accounts: deleted after 3 years without any sign-in, after an email notice.
Appointments: as long as the account exists. If you delete your account, they are no longer linked to you; the professional keeps the consultation record in their space, under their responsibility and according to the obligations that apply to them.
Search assistant conversations: 12 months after the last message, with automatic daily deletion.
IP address fingerprint used to limit abuse: 7 days. Free search counter linked to the website session: 12 months.
Reviews: as long as the professional's profile is published. If you delete your account, approved reviews are anonymised and the others erased.
Professional verification documents: as long as the professional's account exists, to evidence the verification, and erased within 30 days after the account is closed.
Invoices and billing data: 10 years, the legal retention period for tax and accounting records.
Support requests: until the account is deleted and at most 3 years after the request is closed.
Contact form messages: 3 years after the last exchange.
Reminder and notification history: as long as the professional's account exists.
Google Calendar events: as long as the connection is active; they are erased when the professional disconnects it.
Server technical logs: 30 days.
Marketing consent: until you withdraw it.
Where the law requires it, or to defend a right in a dispute, some data may be kept longer, solely for that purpose.
Cookies and browser storage
We use no advertising or audience measurement cookies. We only use cookies and local storage that are strictly necessary for the service or for the preferences you choose, which do not require consent:
Session (sb-…-auth-token cookies, from Supabase): keeps you signed in to the platform.
Language (docagora_lang on the platform, NEXT_LOCALE on the website): remembers the chosen language for 1 year.
Sign-in (auth_portal_role, 10 minutes) and Google Calendar connection (google_oauth_state, 10 minutes): protect these processes.
Clinic (docagora-pro-context, 30 days): remembers the professional selected by front desk staff.
Display preferences (agenda_status_filters, sidebar_state and, in local storage, docagora-theme and agenda_hide_weekend): calendar filters, side menu, light or dark theme.
Search assistant (local storage docagora_anon_chat_session, docagora_anon_chat_remaining and docagora_anon_chat_count): random session identifier and number of free searches left.
Session storage (doca-loaded, docagora:inscription-en-attente, docagora_chat_handoff): loading animation, sign-up confirmation and continuing your search after signing in.
Third-party services without cookies: icons (Font Awesome) and maps (OpenStreetMap) are loaded from these providers' servers, which receive your IP address.
Audience measurement: not active. If we enable it, it will only run after your consent, requested in a notice that lets you refuse as easily as accept; your choice is stored locally (docagora-consent).
Security
We apply technical and organisational measures suited to the sensitive nature of health data: encrypted connections (HTTPS), a database hosted in the European Union with encryption of stored data, access control by role and by data row, encrypted calendar access tokens, passwords never stored in plain text, error logs without identifying data and team access limited to what is necessary. No system is infallible: in the event of a personal data breach that poses a risk, we notify the CNPD and, where required, the people affected.
Your rights
Under the GDPR, you have the right of access, rectification, erasure, restriction of processing, portability and objection, as well as the right to withdraw your consent at any time, without affecting the lawfulness of earlier processing.
In the patient area, in your account settings, you can download all your data in a file and delete your account. Deletion is refused while you have upcoming appointments: cancel them first.
For any other request, or if you are a professional, write to the DPO: jimmydiallo@docagora.pt. We may ask you to confirm your identity.
We reply within one month, which may be extended by two months for complex requests, in which case we will let you know.
For data that a professional records about you as a patient, contact that professional; we pass on any requests we receive.
Minors
Accounts are personal and intended for people aged 18 or over. Appointment requests for a minor are made by a parent or legal guardian from their own account.
Right to lodge a complaint
If you believe the processing of your data breaches the law, you can lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD), the Portuguese supervisory authority: www.cnpd.pt. You can also contact our DPO first, who will try to resolve the matter.
Changes to this policy
We may update this policy to reflect changes to the service or the law. The date of the last update appears at the top of the page. For any significant change, we will inform you by email or on the platform before it takes effect.