Privacy Policy
Effective from: 1 September 2026 · Version: 1.0
1. Data controller
KM+CLINIC, UAB, company code 306250309, Konstitucijos pr. 15-84, LT-09319 Vilnius, Lithuania, tel. +370 626 45003, email info@kmclinic.lt.
2. What we process
| Data | When collected |
|---|---|
| Name, phone number, email address | When placing an order |
| Delivery details (chosen parcel locker) | When placing an order |
| Order data: items, quantities, prices, VAT, payment status | On purchase |
| Correspondence | When you contact us about an order |
| Consent to receive news | Only if the separate box is ticked |
We never collect or store card details — these are handled by our payment provider, Stripe.
3. Purposes and legal bases
| Purpose | Legal basis | Retention |
|---|---|---|
| Fulfilling the order, delivery, warranty | Performance of a contract (GDPR Art. 6(1)(b)) | 10 years |
| Accounting | Legal obligation (Art. 6(1)(c)) | 10 years |
| Handling complaints | Legitimate interest (Art. 6(1)(f)) | Until the period expires |
| News and offers | Consent (Art. 6(1)(a)) | Until consent is withdrawn |
Buying something is not consent to receive marketing — that has its own, unticked box.
If the Buyer is also a patient of the clinic, their health data is processed under the clinic's separate privacy policy and different retention periods apply. Order data is not linked to health data.
4. Recipients
Data is shared only as far as needed to fulfil the order:
| Recipient | Purpose | Processed in |
|---|---|---|
| Stripe | Payment processing | EU / US (Standard Contractual Clauses) |
| DPD Lietuva | Delivery: name, phone, locker | EU |
| MailerSend | Sending email | EU |
| GatewayAPI | Sending SMS | EU |
| Accounting service provider | Bookkeeping | EU |
Data processing agreements (GDPR Art. 28) are in place with all recipients. We do not sell data and do not use it for profiling or automated decision-making.
5. Your rights
You have the right to access your data; to have inaccurate data corrected; to erasure; to restriction of processing; to data portability; to object to processing; and to withdraw consent to marketing at any time.
Write to info@kmclinic.lt. We reply within 30 days.
Note: the right to erasure does not extend to order data we are required to keep under accounting law (10 years).
If you believe your rights have been infringed, you may lodge a complaint with the State Data Protection Inspectorate (L. Sapiegos g. 17, LT-10312 Vilnius, www.vdai.lrv.lt).
6. Security
Phone numbers and email addresses are encrypted in the database (AES-256-GCM). Access to order data is limited to authorised staff, and all actions are recorded in an audit log. The site uses HTTPS.
7. Booking a visit, and health data
This section covers the booking form on the site and the visit to the clinic.
What the form gives us: your name, phone number, e-mail (optional), the service and time you chose, and your message if you wrote one.
What happens to it: the request goes into the clinic's system and waits for a receptionist to call you. Until it is confirmed you are not in the patient records — if the request is rejected, or you withdraw it, it is deleted entirely, contact details included. A patient record is created only when the visit is confirmed.
Legal basis: GDPR Art. 6(1)(b) (performance of a contract for the service). For health data, GDPR Art. 9(2)(h) (health care). For marketing, only your separate consent, which you may withdraw at any time.
How it is stored: phone number, e-mail, date of birth and address are held encrypted (AES-256-GCM). Searching uses one-way cryptographic hashes, not the number itself.
How long: medical records for the period the law requires; order documents for 10 years (accounting); the log of actions on data for 15 years.
Who else sees it: e-mail is sent by MailerSend (Vilnius), SMS by GatewayAPI (EU). They receive only what is needed to deliver the message. An SMS never names the procedure — a text is readable on a lock screen, so it carries only the time and the clinic.
Server: DigitalOcean, Frankfurt (EU). Booking data is processed inside the EU only. The one transfer outside the EU is payment processing through Stripe (see section 4), under standard contractual clauses.
8. Cookies
The site sets no cookies that require consent — no analytics, no advertising. That is also why there is no consent banner. See the Cookie policy for detail.