Privacy policy
Last updated: 30 August 2026
Doctigo helps you find doctors in Luxembourg and book appointments online. Because an appointment can reveal information about your health, we treat everything you share with us with the highest level of care. This policy explains what we collect, why, where it is stored, and the rights you have over it.
Who we are
Doctigo is operated by Aevux S.à r.l.-S, established in Luxembourg. Luxembourg Trade and Companies Register (RCS) number: B292496. Doctigo operates the doctigo website and booking platform. For any question about your data, contact us at guilherme.sequeira@aevux.com.
When you book an appointment, the practitioner you choose receives the booking details and becomes independently responsible for the medical records they keep about you, under their own professional and legal obligations, including medical secrecy.
Responsibility for your data is shared, and which part matters depends on what you are asking about. Your practitioner is responsible for the appointment itself, the reason for your visit, and the medical records that follow from it. Doctigo handles that information on their instructions.
Doctigo is responsible for the parts it runs on its own account: the directory of practitioners, your patient account, the waiting list, the reminders we send you, and any review you publish.
So ask your practitioner about your appointment or your medical records, and ask us about your account, our emails, or how you appear on the site. If you are not sure which, write to us and we will point you to the right place.
Who this policy covers
It covers patients and visitors who browse the site, book appointments as a guest, or create a patient account, and practitioners and their front-desk staff who use Doctigo to manage the agenda and bookings.
The data we collect
We collect only what the service needs to work:
- Account data: your name, email address, optional phone number, and a password we never store in readable form (only a cryptographic hash). We also record when you confirmed your email address, the language you chose for the site, and the moment you gave your consent together with the version of the text you agreed to.
- Booking data: the practitioner, the date and time, and your contact details. You do not type the reason for your visit: you choose it from the list the practice has set up, and it is required whenever the practice has set up any reasons at all. A practice can also make your phone number mandatory.
- Your social security number, only when the practice asks for it: some practices need the 13-digit CNS matricule, which is a national identification number. It is off by default, and the booking form does not show the box unless that practice has switched it on. If it is switched off, a number sent to us anyway is discarded rather than stored. When you do give it, with your explicit consent as part of the booking, it is visible only inside that practice's own agenda: never in a confirmation email, never on the waiting-room screen, never anywhere on the public site.
- Your postal address, on the same basis: street, postcode and town, asked for as a set or not at all, and only when the practice has switched that on. The postcode is deliberately not restricted to the Luxembourg format, because many patients live over the border. As above, not asked for means not stored, and an address that reaches us anyway is discarded. It stays inside that practice's agenda.
- Your date of birth, your gender, or a note for the practitioner, each only when that practice has switched it on individually. The same rule applies: not asked for means not stored, and whatever you do give stays inside that practice's own agenda.
- At the practice, on the day: if the front desk checks you in when you arrive and marks you as called in, we record those two times, so the waiting-room screen is accurate. We also record whether an appointment was completed or missed, and which staff account entered a booking the practice made for you.
- Waiting list: if you join a queue for an earlier slot, we keep the hour you are waiting for, your contact details, the same reason for visit, your language, your place in the queue, and the offers we send you, including when each one expires and how you answered. The practice may also keep a short internal note about your entry, for its own queue management; it is never shown to you or published.
- Reviews: what you write, and whether you asked to appear anonymously. What happens to a review once you post it is described under “Who can see your data”.
- Health data: the reason for visit, any note you add for the practitioner, anything you write in a review, and the fact that you have an appointment with a particular practitioner, can all reveal information about your health. We collect it solely with your explicit consent, which you give at the moment you act: making a booking, creating your account, joining a waiting list, or posting a review. We record when you gave it and the version of the text you agreed to.
- Practitioner data: the professional profile practitioners publish (name, photo, description, specialty, practice address, languages), the list of reasons for visit they offer, their availability, time off and closures, and their subscription tier. When a practice saves its address, we ask a mapping service to place it correctly on the search map; no patient data is involved in that request.
- Technical and security data: connection information such as your IP address, kept briefly in our database to count requests against a limit and stop automated abuse. It is held for the length of that limit, at most an hour, and is never built into a profile of you. For practitioner and front-desk accounts that turn on two-step sign-in, we store the second-factor setup, single-use backup codes, and, if you ask us to remember a browser for 15 days, a token for that browser and a short description of it. Our own application logs are deliberately written without names, email addresses, or any health information.
- When you write to us: the contact form keeps the topic you picked, your name, your email address, and your message.
Why we process it, and on what legal basis
Every use of your data maps to a purpose and a legal basis under the GDPR:
- Providing the booking service: creating your appointment, sending it to your practitioner, letting you view and cancel it (Article 6(1)(b), performance of a contract).
- Processing the reason for your visit and other health-revealing data: only with your explicit consent (Article 9(2)(a) together with Article 6(1)(a)). You can withdraw it, and “Your rights” below explains what withdrawing means in practice.
- Keeping the platform secure: rate limiting, abuse prevention, and account protection (Article 6(1)(f), our legitimate interest in a safe service).
- Meeting legal obligations that apply to us in Luxembourg (Article 6(1)(c)).
We never sell your data, we show no advertising, and we do not use your data to train artificial-intelligence models.
Who can see your data
Access is limited to what each party strictly needs:
- The practitioner you book with, and any front-desk staff they have authorised, see your booking details, including your contact information and the reason for your visit: they are treating you, and this is the purpose of the service. The waiting-room screen at the desk deliberately leaves your social security number out.
- Other patients and other practitioners see nothing about you, with one exception that is yours to make. A review you post appears on that practitioner's public profile, where anyone can read it, with what you wrote and your first name. If you post anonymously, your name is shown to nobody, not to other patients and not to the practitioner either. A practice can choose to publish a review without the written comment, or to hide it from the public altogether.
- Our providers handle data on our behalf: the company that runs our database and file storage, the company that runs our application servers, and the provider that delivers our emails. They run infrastructure for us and have no purpose of their own for what passes through it. Each of them is bound to that by a written data-processing agreement. Our emails are deliberately thin: the delivery provider sees your name, your email address, the appointment date and time, the practitioner's name and the practice address, and never the reason for your visit and never the specialty, because naming the specialty would say something about your health on its own. If your practice sends appointment reminders by text message, that same provider also delivers those, which means it receives your mobile number. The text itself says only that you have an appointment and when: never the practitioner's name, never the specialty and never the reason for your visit.
- Our own team accesses personal data only when it is needed to operate the service or to answer a request from you. Administrative access requires a second sign-in factor once it has been set up on the account.
- The map on the search results page loads its background tiles straight from a third-party map service. That service sees your IP address and the area of the map you are looking at, and nothing else: not who you are, and not which practitioner you open.
- The practice address on a practitioner's profile is a link to Google Maps. The map is not embedded, so nothing reaches Google while you read the page: the link does something only if you choose to click it, and it is set not to tell Google which page you came from. Once you are on Google Maps, Google's own terms and privacy policy apply.
Where your data lives
Your account, booking, waiting-list and review data is stored on infrastructure in the European Union, in Frankfurt, Germany. Our application servers, and the layer that carries your requests to them, are configured to run there too.
Some of the companies that run this infrastructure for us are headquartered outside the EU. Where that applies, the transfer is covered by the safeguards the GDPR requires, such as the European Commission's Standard Contractual Clauses, which are in place with each provider alongside the data-processing agreements described above.
Our public website is delivered through a global content-delivery network so pages load quickly wherever you are, and everything you submit travels over encrypted connections.
How long we keep it
Your account exists until you ask us to delete it. Appointment records are kept while they remain necessary for your relationship with your practitioner and for the legal retention duties that apply to healthcare-related records.
Nothing is deleted automatically. There is no job that quietly clears old records, and health-related records are never silently erased: deletion is an action a person takes, on request. When we do erase, we check afterwards that the records are really gone, and we keep a record of what was removed, what was kept, and why.
Two honest limits on that. Copies can remain for a period in our hosting provider's encrypted backups, and the provider that delivered your emails keeps its own delivery records. To request deletion of your account and data, write to guilherme.sequeira@aevux.com.
How we protect it
Security is the first requirement of everything we build:
- All connections are encrypted in transit, and our hosting provider encrypts data at rest on the infrastructure it runs for us.
- Passwords and login sessions are stored only as cryptographic hashes; even a copy of our database would not reveal a usable password or session.
- Access to appointment data is enforced server-side on every single request: you can only ever read your own bookings, and a practice account only ever the agendas it is responsible for.
- The database is locked down so that only our own application can read it. Every table refuses the hosting provider's data interface, so a leaked key to that interface would return nothing.
- Sign-in, registration, booking and our other sensitive endpoints are rate-limited to resist automated attacks.
- Our own application logs are written without names, email addresses, or health information.
The links we email you
Some of our emails contain a link that acts on an appointment without a password, because there is not always an account behind a booking. The confirmation email for a guest booking carries a link that cancels the appointment, and it stays valid well beyond the appointment date. A waiting-list email carries a link that accepts the offered slot, and that one works only once.
Anyone who can read the mailbox can use those links, so please do not forward these emails. A link always shows you what it is about to do and waits for you to confirm before it does it.
Cookies
We use three cookies, and none of them tracks you: one keeps you signed in to your account, one remembers your language, and one, only on practitioner and front-desk accounts and only if you ask us to remember a browser, lets that browser skip the second sign-in step for 15 days. Signed-in staff also carry the standard session and anti-forgery cookies our administration interface needs. We set no analytics, advertising, or tracking cookies, which is why you see no cookie banner.
Your rights
Under the GDPR you can, at any time and free of charge:
- access the data we hold about you and receive a copy (Article 15);
- correct inaccurate data (Article 16);
- have your data erased (Article 17);
- restrict or object to certain processing (Articles 18 and 21);
- receive your data in a portable format (Article 20);
- withdraw your consent to health-data processing, without affecting the lawfulness of what was done before you withdrew.
Write to guilherme.sequeira@aevux.com and we will respond within one month. There is no button for any of this: these are requests a person handles. Withdrawing your consent for health-related data means that data is erased, except where your practitioner has to keep a record of your care.
For anything about your appointment or your medical record, your practitioner decides and we act on their instruction, so write to them or ask us to pass it on. You also have the right to lodge a complaint with the Luxembourg supervisory authority, the Commission nationale pour la protection des données (CNPD), at cnpd.lu.
Children
Patient accounts are for people aged 16 or older. We do not ask for a date of birth, so this is a rule we ask you to respect rather than a check we run. Parents and legal guardians may book appointments on behalf of their children; the guardian's account holds the booking, and the child's information receives the same health-data protections described above.
Changes to this policy
When we change this policy in any meaningful way, we will update the date at the top and, for significant changes, inform you in the app or by email.
Contact
Doctigo, operated by Aevux S.à r.l.-S, Luxembourg. RCS Luxembourg: B292496. Email: guilherme.sequeira@aevux.com.
Doctigo is a booking platform, not an emergency service. In a medical emergency, call 112.