Privacy Policy
Last updated: 2026-04-26
This Privacy Policy explains how BLITZ ENTERPRISES S.R.L. ("BlitzClinic", "we", "us") collects, uses, shares, and protects personal data collected on the public BlitzClinic sales website (blitzclinic.com), including demo, contact, pricing, buy, checkout and company-data forms. It also clarifies the boundary between the public website and logged-in/internal BlitzClinic apps, such as the clinic management platform. The sales website does not collect patient health data; clinic platform data is processed separately under customer agreements and Data Processing Agreements. We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR) and all applicable data protection laws.
1. Data Controller
The data controller for personal data collected through the public BlitzClinic sales website is: BLITZ ENTERPRISES S.R.L. Address: București Sectorul 1, Strada Pitar Moș, Nr. 27, Etaj 5, Ap. 17, Romania CUI: 54399335 Trade Registry: J2026021644001 EUID: ROONRC.J2026021644001 Email: [email protected] Data Protection Officer: [email protected] When clinics use logged-in BlitzClinic apps to process clinic, patient or health data, that data is not collected from the public sales website. In those app contexts, the clinic acts as the data controller and BlitzClinic acts as the data processor under a customer agreement and Data Processing Agreement.
2. Data We Collect
On the public BlitzClinic sales website, we collect the following categories of personal data: Website Contact & Lead Data: name, email address, phone number, job title, clinic or company name, tax identification number (CUI/CIF), billing address, country/city, message content, selected package, company details and preferences submitted through demo, contact, pricing, buy, checkout and company-data forms. Checkout & Payment Data: checkout status, subscription details, selected package, Revolut order identifiers, payment references, transaction records and invoicing records. Full payment card details are processed by Revolut and are never stored on our servers. Usage Data: IP address, browser type and version, device information, operating system, pages visited, time spent on pages, referral source and click patterns. Cookie Data: preferences, session identifiers, analytics identifiers and marketing identifiers. See our Cookie Policy for details. Communication Data: messages and requests you send through the public website, demo requests, support or sales inquiries, and related response metadata. Lead, Checkout & Attribution Data: consent status, form step/progress, event name, event time, event source URL, action source, event ID, referrer, campaign/source parameters, Google Tag Manager and Google Analytics identifiers, Meta Pixel and Meta Conversions API identifiers (_fbp, _fbc), IP address, user agent and device/browser information. Advertising Matching Data: where you consent to marketing tracking, we may send Meta hashed customer information such as email, phone, first name, last name, city, state/region, postal code, country, date of birth, gender and external ID, together with technical parameters Meta requires for matching, such as IP address, user agent, _fbp, _fbc and subscription ID. What the sales website does not collect: the public website does not collect patient medical records, treatment plans, dental charts, prescriptions, clinical notes, medical imaging, health history or other health data. Clinic, patient and health data may be processed only when a clinic uses logged-in/internal BlitzClinic apps, such as the clinic management platform. That data is not collected from blitzclinic.com sales pages, is not sold, and is not used for advertising matching.
3. Legal Basis for Processing
We process public sales website personal data under the following legal bases as defined in GDPR Article 6: Contract Performance (Art. 6(1)(b)): Processing necessary to respond to demo, buy and checkout requests, create checkout orders and subscriptions, process payments through Revolut, and deliver related customer support. Legitimate Interest (Art. 6(1)(f)): Website security and fraud prevention, service improvement, non-marketing analytics, deduplicating browser and server events, and business-to-business sales follow-up where you have contacted us or shown interest in our services (with opt-out). Consent (Art. 6(1)(a)): Marketing cookies and tracking, Google Analytics, Google Tag Manager where used to load non-essential tags, Meta Pixel, Meta Conversions API, advanced matching/customer information parameters, advertising event measurement, and marketing communications to prospective customers. Legal Obligation (Art. 6(1)(c)): Tax and accounting records, responding to lawful requests from authorities, and payment/invoicing retention requirements. Health, clinic and patient data processed inside logged-in/internal BlitzClinic apps is not collected through the public sales website and is governed by the relevant clinic customer agreement and Data Processing Agreement.
4. How We Use Your Data
We use public sales website personal data for the following purposes: • Responding to demo, contact, pricing, buy, checkout and company-data requests • Capturing, qualifying and following up on leads from public website flows • Creating Revolut checkout/payment orders, reconciling payment status and managing subscription setup • Sending website and checkout communications, such as confirmations, receipts and service notifications • Providing customer support and responding to inquiries • Ensuring website security, detecting fraud, and preventing abuse • Analyzing website usage patterns to improve performance and user experience • Generating anonymized and aggregated analytics and reports • Measuring consented marketing funnels and conversion events, such as View Content, Lead, Complete Registration, Contact, Initiate Checkout, Add Payment Info, Add to Cart, Purchase, Subscribe, Start Trial, Schedule, Search and Submit Application where applicable • Deduplicating browser-side and server-side conversion events with event IDs so Google Tag Manager/browser events and Meta Conversions API events are not counted twice • Sending marketing communications about our services (with your consent or based on legitimate interest, with opt-out available) • Complying with legal and regulatory obligations We do not use the sales website to collect patient health records, and we do not use clinic, patient or health data from logged-in/internal apps for advertising matching.
5. Data Sharing & Processors
We share public sales website personal data with the following categories of third-party processors, each bound by data processing agreements where required: Cloudflare, Inc. (United States, EU data centers) — Content delivery network (CDN), DDoS protection, R2 object storage for files and documents, Turnstile bot protection. Cloudflare processes data primarily in EU data centers. Google LLC (United States) — Google Tag Manager for consent-based tag orchestration and Google Analytics for website traffic analysis and user behavior insights. Data is anonymized where possible. Meta Platforms, Inc. (United States) — Meta Pixel and Meta Conversions API for measuring advertising effectiveness, attribution, remarketing and conversion optimization on the public sales website. Where you consent, Meta may receive event details such as event time, event name, source URL, action source and event ID; technical matching parameters such as IP address, user agent, _fbp and _fbc; and hashed customer information such as email, phone, name, location, date of birth, gender and external ID. Hetzner Online GmbH (Germany) — Hosting and infrastructure for website/backend services where used. Production data is hosted in Hetzner's German data centers within the EU. Microsoft Corporation — Azure (EU West region) — Azure Key Vault for secrets management and Azure Kubernetes Service (AKS) for container orchestration where used. Data is processed within the EU. Revolut Ltd (United Kingdom / EU) — Checkout order creation, payment processing, subscription billing and payment status reconciliation. Revolut is authorized by the Financial Conduct Authority and complies with PSD2. Full card details are handled by Revolut and are not stored by BlitzClinic. We do not sell sales website personal data. We also do not sell clinic, patient or health data processed in logged-in/internal BlitzClinic apps. We may disclose data if required by law, court order, or to protect our legal rights.
6. International Data Transfers
Your data is primarily stored and processed within the European Union (Germany and EU West regions). Where data is transferred to processors outside the EU/EEA (United States, United Kingdom), we ensure adequate protection through: • EU Standard Contractual Clauses (SCCs) as approved by the European Commission • Adequacy decisions where applicable (e.g., UK under the EU-UK Trade and Cooperation Agreement) • Supplementary technical measures including encryption in transit and at rest All international transfers are documented and assessed for risk in accordance with GDPR Chapter V requirements. You may request a copy of the relevant transfer safeguards by contacting [email protected].
7. Data Retention
We retain public sales website personal data only for as long as necessary to fulfill the purposes for which it was collected: • Lead and sales follow-up records: retained while the sales relationship is active and then up to 3 years, unless you ask us to delete them earlier or legal obligations require a longer period • Checkout, payment and invoicing records: retained for 10 years where required by Romanian fiscal legislation • Revolut order identifiers and payment references: retained with payment and invoicing records where required for accounting, chargeback and audit purposes • Marketing consent records: retained for the duration of consent plus 3 years • Conversion event logs, event IDs and attribution data: retained only as needed for deduplication, audit, attribution and the retention windows of the relevant advertising or analytics provider • Usage and analytics data: retained in anonymized form; raw data deleted after 26 months • Cookie data: retention varies by cookie type (see Cookie Policy) Retention for clinic, patient and health data processed in logged-in/internal BlitzClinic apps is governed by the relevant clinic customer agreement and Data Processing Agreement, not by public sales website collection. When data is no longer needed, it is securely deleted or anonymized using industry-standard methods.
8. Your Rights
Under the GDPR, you have the following rights regarding your personal data: Right of Access (Art. 15): Request a copy of the personal data we hold about you. Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data. Right to Erasure (Art. 17): Request deletion of your personal data where there is no compelling reason for continued processing. Right to Restriction (Art. 18): Request that we limit the processing of your data in certain circumstances. Right to Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format (CSV, JSON). Right to Object (Art. 21): Object to processing based on legitimate interest or for direct marketing purposes. Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing. Right Not to Be Subject to Automated Decision-Making (Art. 22): Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects. To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. If your request is complex, we may extend this by an additional 60 days with notice. There is no fee for exercising your rights unless requests are manifestly unfounded or excessive.
9. Health Data and Internal Apps
The public sales website at blitzclinic.com does not collect health data. We do not ask website visitors to submit patient medical records, diagnoses, treatment plans, dental charts, prescriptions, clinical notes, medical imaging, health history or similar health information through the sales website. Health, clinic and patient data may be processed only when a clinic uses logged-in/internal BlitzClinic apps, such as the clinic management platform. In those contexts, the clinic acts as the data controller and BlitzClinic acts as the data processor under the relevant customer agreement and Data Processing Agreement. We do not sell clinic, patient or health data processed in logged-in/internal apps. We also do not use that data for Meta, Google or other advertising matching. Clinics are responsible for obtaining valid patient consent and maintaining records of consent as required by GDPR and applicable healthcare regulations.
10. Cookies
We use cookies, pixels, tags, local storage and server-side conversion events on the public sales website. For detailed information about the types of cookies we use, their purposes, and how to manage your preferences, please refer to our Cookie Policy available at https://blitzclinic.com/legal/cookies. Google Tag Manager may be used to load analytics and marketing tags according to your consent choices. Meta Pixel may collect browser-side events, and Meta Conversions API may send matching server-side events from our backend. We use shared event IDs to deduplicate browser and server events. Where applicable and consented, sales website events may include View Content, Lead, Complete Registration, Contact, Customize Product, Initiate Checkout, Add Payment Info, Add to Cart, Add to Wishlist, Purchase, Subscribe, Start Trial, Schedule, Search, Submit Application, Donate and Find Location. Event payloads may include event time, event name, event source URL, action source, event ID, opt-out or data-processing flags, IP address, user agent, _fbp, _fbc, country, city, state/region, postal code, date of birth, email, external ID, first name, last name, gender, phone and subscription ID. Identifiers are hashed where Meta requires hashing; IP address, user agent, _fbp, _fbc and subscription ID are sent unhashed where Meta requires unhashed values. These technologies load only with consent where required. Necessary security, fraud-prevention and payment/contract events may still be processed where needed to provide the public website, checkout or requested service. We do not send health records, full card numbers or government-issued identity documents to advertising platforms, and these technologies are not used to read or collect clinic, patient or health records from logged-in/internal BlitzClinic apps. You can manage your cookie preferences at any time through the cookie consent banner on our website.
11. Data Security
We implement technical and organizational measures to protect public sales website personal data and related backend services: • Encryption: TLS 1.2+ in transit and encryption at rest where applicable • Infrastructure: Production systems hosted in certified EU data centers where used, with controlled deployment and orchestration • Access Control: Role-based access control (RBAC), multi-factor authentication, principle of least privilege • Monitoring: Security monitoring, intrusion detection, anti-abuse controls and alerting • Backups: Encrypted backups for relevant systems with tested recovery procedures • Secrets Management: Credentials and API keys stored in managed secret stores such as Azure Key Vault, never in source code • Audit Logging: Access and operational logs for relevant systems • Network Security: HTTPS-only traffic and network restrictions for backend services • Incident Response: Documented incident response plan with defined roles, escalation procedures and notification timelines compliant with GDPR Article 33 where applicable We regularly review and update our security measures to address emerging threats.
12. Children's Privacy
The public BlitzClinic sales website is intended for clinic owners, healthcare professionals, clinic staff, partners and other business visitors. It is not intended for direct use by children under the age of 16, and it does not collect patient records of children. Where patient records of minors are processed inside logged-in/internal BlitzClinic apps, this is done under the responsibility of the clinic (data controller) with appropriate parental or guardian consent as required by applicable law. If we become aware that the public sales website has collected personal data from a child under 16 without appropriate consent, we will take steps to delete that data promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated to registered users via email and/or in-platform notification at least 30 days before taking effect. The "Last updated" date at the top of this policy indicates when it was last revised. We encourage you to review this policy periodically. Continued use of the platform after changes take effect constitutes acceptance of the updated policy.
14. DPO Contact & Supervisory Authority
Data Protection Officer Email: [email protected] BLITZ ENTERPRISES S.R.L. București Sectorul 1, Strada Pitar Moș, Nr. 27, Etaj 5, Ap. 17, Romania You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated. The competent supervisory authority for Romania is: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) Address: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București, Romania Phone: +40.318.059.211 Email: [email protected] Website: https://www.dataprotection.ro If you are located in another EU/EEA member state, you may also contact your local data protection authority.