AlfaServices – Privacy Policy

Last updated: Feb 2026

1. Introduction

This Privacy Policy explains how AlfaServices collects, uses, stores, and protects personal data when providing its Software as a Service (SaaS) platform to users located in the European Union, the United States, and Iran.AlfaServices is committed to protecting personal data and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), relevant U.S. privacy laws, and Iranian data protection regulations.

2. Roles and Responsibilities

  • Doctors / Clients act as Data Controllers with respect to patient and end-user data collected through their websites.
  • AlfaServices acts as a Data Processor and technical service provider, processing data only on documented instructions from the Doctor.

3. Data We Collect

Depending on usage, we may collect the following categories of data:
  • Account information (name, email, contact details)
  • Website and appointment-related data
  • Patient-submitted information through booking forms
  • Technical data (IP address, device type, logs, cookies)
AlfaServices does not intentionally collect sensitive medical data unless technically required for appointment functionality and instructed by the Doctor.

4. Purposes and Legal Bases for Processing

Personal data is processed for the following purposes:
  • Providing and maintaining the Service
  • Managing accounts and subscriptions
  • Enabling appointment booking functionality
  • Ensuring platform security and performance
  • Complying with legal obligations
Legal bases may include:
  • Performance of a contract
  • Legitimate interests
  • User consent (where required)
  • Compliance with legal obligations

5. Data Sharing and Third Parties

Personal data may be shared with trusted third parties such as:
  • Hosting and infrastructure providers
  • Payment processors
  • Analytics and security service providers
All third parties are contractually obligated to protect data and process it in compliance with applicable laws.

6. International Data Transfers

Personal data may be processed or stored outside the user’s country of residence. Where required by law, appropriate safeguards such as Standard Contractual Clauses (SCCs) are implemented.

7. Data Retention

Personal data is retained only for as long as necessary to fulfill the purposes described in this Policy or as required by law. Upon termination of services, data may be deleted after a reasonable retention period.

8. Data Subject Rights

Depending on applicable law, users may have the right to:
  • Access their personal data
  • Request correction or deletion
  • Object to or restrict processing
  • Withdraw consent
  • Lodge a complaint with a supervisory authority
Requests can be submitted via the contact details below.

9. Security Measures

AlfaServices implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse. However, no system can guarantee absolute security.

10. Cookies and Tracking Technologies

Cookies and similar technologies are used in accordance with our Cookie Policy to ensure functionality, preferences, and analytics (where consent is provided).

11. Governing Law

This Privacy Policy is governed by applicable data protection laws based on the user’s location:
  • European Union: GDPR and applicable national laws
  • United States: Applicable federal and state privacy laws
  • Iran: Applicable Iranian laws and regulations