Privacy policy
Last updated: 3 July 2026
Doctigo helps you find doctors in Luxembourg and book appointments online. Because an appointment can reveal information about your health, we treat everything you share with us with the highest level of care. This policy explains what we collect, why, where it is stored, and the rights you have over it.
Who we are
Doctigo is operated by X, established in Luxembourg and registered with the Luxembourg Trade and Companies Register (RCS) under number X. Doctigo operates the doctigo website and booking platform and is the controller of the personal data described in this policy. For any question about your data, contact us at X.
When you book an appointment, the practitioner you choose receives the booking details and becomes independently responsible for the medical records they keep about you, under their own professional and legal obligations, including medical secrecy.
Who this policy covers
It covers patients and visitors who browse the site, book appointments as a guest, or create a patient account, and practitioners who use Doctigo to manage their agenda and bookings.
The data we collect
We collect only what the service needs to work:
- Account data: your name, email address, optional phone number, and a password we never store in readable form (only a cryptographic hash).
- Booking data: the practitioner, date and time, your contact details, and, only if you choose to provide it, the reason for your visit.
- Health data: the reason for visit, and the fact that you have an appointment with a particular practitioner, can reveal information about your health. We collect it solely with your explicit consent, given when you make the booking or create your account, and we record the moment you gave it.
- Practitioner data: the professional profile practitioners publish (name, specialty, practice address, languages, availability).
- Technical and security data: connection information such as your IP address, processed transiently to protect the platform against abuse (for example, limiting repeated login attempts). Our application logs are deliberately written without names, email addresses, or any health information.
Why we process it, and on what legal basis
Every use of your data maps to a purpose and a legal basis under the GDPR:
- Providing the booking service: creating your appointment, sending it to your practitioner, letting you view and cancel it (Article 6(1)(b), performance of a contract).
- Processing the reason for your visit and other health-revealing data: only with your explicit consent (Article 9(2)(a) together with Article 6(1)(a)). You can withdraw it at any time.
- Keeping the platform secure: rate limiting, abuse prevention, and account protection (Article 6(1)(f), our legitimate interest in a safe service).
- Meeting legal obligations that apply to us in Luxembourg (Article 6(1)(c)).
We never sell your data, we show no advertising, and we do not use your data to train artificial-intelligence models.
Who can see your data
Access is limited to what each party strictly needs:
- The practitioner you book with sees your booking details, including your contact information and the reason for visit if you provided one: they are treating you, and this is the purpose of the service.
- Other patients and other practitioners see nothing about you.
- Our hosting and infrastructure providers process data on our behalf as processors, bound by data-processing agreements, and cannot use it for their own purposes.
- Our own team accesses personal data only when strictly necessary to operate the service or answer your requests, under least-privilege access controls.
Where your data lives
Your account and booking data, including anything health-related, is processed and stored on infrastructure located in the European Union, in Frankfurt, Germany.
Our public website is delivered through a global content-delivery network so pages load quickly wherever you are; the personal data you submit is transmitted over encrypted connections to our systems in the EU. Where any supporting provider operates outside the EU, transfers are protected by the safeguards the GDPR requires, such as the European Commission's Standard Contractual Clauses.
How long we keep it
Your account exists until you ask us to delete it. Appointment records are kept while they remain necessary for your relationship with your practitioner and for the legal retention duties that apply to healthcare-related records.
Health-related records are never silently erased: deletion is a deliberate, logged operation, so there is always an answer to the question of what happened to your data. To request deletion of your account and data, write to X.
How we protect it
Security is the first requirement of everything we build:
- All connections are encrypted in transit, and data is encrypted at rest.
- Passwords and login sessions are stored only as cryptographic hashes; even a copy of our database would not reveal a usable password or session.
- Access to appointment data is enforced server-side on every single request: you can only ever read your own bookings, and a practitioner only ever their own agenda.
- Login, registration, and booking endpoints are rate-limited to resist automated attacks.
- Application logs never contain names, email addresses, or health information.
Cookies
We use only strictly necessary cookies: one that keeps you signed in to your account, and one that remembers your language. Both are essential for the service to function. We set no analytics, advertising, or tracking cookies, which is why you see no cookie banner.
Your rights
Under the GDPR you can, at any time and free of charge:
- access the data we hold about you and receive a copy (Article 15);
- correct inaccurate data (Article 16);
- have your data erased (Article 17);
- restrict or object to certain processing (Articles 18 and 21);
- receive your data in a portable format (Article 20);
- withdraw your consent to health-data processing at any time, without affecting the lawfulness of what was done before withdrawal.
Write to X and we will respond within one month. You also have the right to lodge a complaint with the Luxembourg supervisory authority, the Commission nationale pour la protection des données (CNPD), at cnpd.lu.
Children
Patient accounts are for people aged 16 or older. Parents and legal guardians may book appointments on behalf of their children; the guardian's account holds the booking, and the child's information receives the same health-data protections described above.
Changes to this policy
When we change this policy in any meaningful way, we will update the date at the top and, for significant changes, inform you in the app or by email.
Contact
Doctigo, operated by X, Luxembourg. RCS Luxembourg: X. Email: X.
Doctigo is a booking platform, not an emergency service. In a medical emergency, call 112.