PRIVACY POLICY
Version dated 10 September 2026
Data controller
The data controller is Dr Efstratios K. Kouroumpas. Contact: info@kouroumpas.gr, +30 210 977 7000, REA MED, 377 Syngrou Avenue & 3 Zisimopoulou Street, 175 64 Palaio Faliro, Greece.
Data collected directly by a hospital, diagnostic centre or other healthcare organisation when an appointment is arranged or care is delivered are also governed by that organisation’s privacy policy; the organisation may act as an independent controller.
Data collected
This website has no contact form, patient account or online booking system. The page URL determines the language without requiring a stored language preference. The hosting provider may process basic technical logs, such as IP address, device type and access time, to operate the service securely and reliably. At present, technical hosting is provided through OpenAI’s ChatGPT Sites service and business email through Papaki/team.blue. If you contact us by telephone or email, we process the information you choose to provide solely to respond or arrange an appointment.
Health data and email
Do not send a complete medical record, test results or other sensitive information by ordinary email. Please call first for instructions on a more secure transfer method when needed.
Purpose, legal basis and retention
Depending on the context, processing relies on steps requested before entering into a contract (GDPR Article 6(1)(b)), a legal obligation (6(1)(c)), or the legitimate interest in operating the website securely and responding to enquiries (6(1)(f)). Health data are processed only where necessary for the provision or management of healthcare under Article 9(2)(h) GDPR and applicable law, by professionals subject to professional secrecy as required by Article 9(3). The website itself does not request health data.
General enquiries are kept only for as long as needed to respond and are then deleted or, where they relate to care, incorporated into the medical record and retained for the period required by law. Technical logs are retained in line with the hosting provider’s retention periods for security and operational logs.
Recipients and international transfers
Access is limited to authorised persons and necessary email, hosting and technical-support providers subject to appropriate confidentiality and data-protection obligations. Personal data are not sold. Where a technical provider transfers data outside the EEA, an adequacy decision, approved Standard Contractual Clauses or another lawful mechanism and any required supplementary safeguards must apply. OpenAI’s Data Processing Addendum describes safeguards used for its technical service.
Your rights
Depending on the circumstances, you may request information, access, rectification, erasure, restriction, portability or object to processing. You may also complain to the Hellenic Data Protection Authority. Some rights are subject to statutory exceptions.
Cookies and analytics
The current version uses no advertising cookies, behavioural tracking or analytics. If this changes, this policy will be updated and consent requested where required.